From: Sven Eckelmann <sven@narfation.org>
To: "Linus Lüssing" <linus.luessing@c0d3.blue>
Cc: b.a.t.m.a.n@lists.open-mesh.org, Sashiko <sashiko-bot@kernel.org>
Subject: Re: [PATCH batadv] batman-adv: dat: initialize orig_node of unfilled candidate slots
Date: Tue, 06 Oct 2026 18:57:30 +0200 [thread overview]
Message-ID: <6321151.lOV4Wx5bFT@sven-desktop> (raw)
In-Reply-To: <asTVqLO0EWAVM_IE@sellars>
[-- Attachment #1: Type: text/plain, Size: 2996 bytes --]
On Tuesday, 6 October 2026 13:04:08 CEST Linus Lüssing wrote:
[...]
> (Also, I can't read the Sashiko link, I guess it's only accessible for
> maintainers?)
I had to login to the sashiko.dev to get access to the "Bugs" section. And
even after login, I can only access the "BATMAN ADVANCED" subsystem. I have no
idea how to make the report readable for everyone. But this is the text:
In the batman-adv Distributed ARP Table (DAT) selection process, if an
early candidate selection round fails to find an eligible node,
batadv_is_orig_node_eligible() reads uninitialized heap memory when
evaluating nodes during subsequent rounds.
The vulnerability stems from batadv_dat_select_candidates() allocating the
candidate array using kmalloc() without zeroing the memory. It then
iteratively calls batadv_choose_next_candidate() to fill each slot. If no
candidate is found during a given iteration, the slot's type is marked as
BATADV_DAT_CANDIDATE_NOT_FOUND, but its orig_node pointer remains
uninitialized. During the next iteration, batadv_choose_next_candidate()
iterates over nodes and calls batadv_is_orig_node_eligible(), which loops
over all previously processed slots (up to the current select index) and
reads res[j].orig_node to verify if the candidate was already selected.
This results in an uninitialized heap memory read during the pointer
comparison, which triggers a KMSAN violation. Because the garbage memory is
used only for equality comparison against active orig_node pointers, the
defect results in undefined behavior and a highly improbable false-positive
candidate match rather than a system crash or memory corruption.
// net/batman-adv/distributed-arp-table.c:182-206
static struct batadv_dat_candidate *
batadv_dat_select_candidates(struct batadv_priv *bat_priv, __be32 ip_dst)
{
int select;
< ... >
struct batadv_dat_candidate *res;
< ... >
res = kmalloc(BATADV_DAT_CANDIDATES_NUM * sizeof(*res), GFP_ATOMIC);
if (!res)
return NULL;
< ... >
for (select = 0; select < BATADV_DAT_CANDIDATES_NUM; select++)
batadv_choose_next_candidate(bat_priv, res, select, ip_key,
&last_max);
return res;
}
// net/batman-adv/distributed-arp-table.c:114-162
static void batadv_choose_next_candidate(...)
{
< ... >
cands[select].type = BATADV_DAT_CANDIDATE_NOT_FOUND;
for (i = 0; i < hash->size; i++) {
< ... >
hlist_for_each_entry_rcu(...) {
< ... >
if (!batadv_is_orig_node_eligible(cands, select, ...))
continue;
< ... >
}
< ... >
}
if (max_orig_node) {
cands[select].type = BATADV_DAT_CANDIDATE_ORIG;
cands[select].orig_node = max_orig_node;
< ... >
}
< ... >
}
// net/batman-adv/distributed-arp-table.c:69-82
static bool batadv_is_orig_node_eligible(...)
{
bool ret = false;
int j;
< ... >
/* Check if this node has already been selected... */
for (j = 0; j < select; j++)
if (res[j].orig_node == candidate)
break;
< ... >
}
[-- Attachment #2: This is a digitally signed message part. --]
[-- Type: application/pgp-signature, Size: 228 bytes --]
prev parent reply other threads:[~2026-10-06 16:57 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-04 8:10 [PATCH batadv] batman-adv: dat: initialize orig_node of unfilled candidate slots Sven Eckelmann
2026-10-06 11:04 ` Linus Lüssing
2026-10-06 16:57 ` Sven Eckelmann [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=6321151.lOV4Wx5bFT@sven-desktop \
--to=sven@narfation.org \
--cc=b.a.t.m.a.n@lists.open-mesh.org \
--cc=linus.luessing@c0d3.blue \
--cc=sashiko-bot@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox