B.A.T.M.A.N Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: Sven Eckelmann <sven@narfation.org>
To: "Linus Lüssing" <linus.luessing@c0d3.blue>
Cc: b.a.t.m.a.n@lists.open-mesh.org, Sashiko <sashiko-bot@kernel.org>
Subject: Re: [PATCH batadv] batman-adv: dat: initialize orig_node of unfilled candidate slots
Date: Tue, 06 Oct 2026 18:57:30 +0200	[thread overview]
Message-ID: <6321151.lOV4Wx5bFT@sven-desktop> (raw)
In-Reply-To: <asTVqLO0EWAVM_IE@sellars>

[-- Attachment #1: Type: text/plain, Size: 2996 bytes --]

On Tuesday, 6 October 2026 13:04:08 CEST Linus Lüssing wrote:
[...]
> (Also, I can't read the Sashiko link, I guess it's only accessible for
> maintainers?)

I had to login to the sashiko.dev to get access to the "Bugs" section. And 
even after login, I can only access the "BATMAN ADVANCED" subsystem. I have no 
idea how to make the report readable for everyone. But this is the text:

In the batman-adv Distributed ARP Table (DAT) selection process, if an
early candidate selection round fails to find an eligible node,
batadv_is_orig_node_eligible() reads uninitialized heap memory when
evaluating nodes during subsequent rounds.

The vulnerability stems from batadv_dat_select_candidates() allocating the
candidate array using kmalloc() without zeroing the memory. It then
iteratively calls batadv_choose_next_candidate() to fill each slot. If no
candidate is found during a given iteration, the slot's type is marked as
BATADV_DAT_CANDIDATE_NOT_FOUND, but its orig_node pointer remains
uninitialized. During the next iteration, batadv_choose_next_candidate()
iterates over nodes and calls batadv_is_orig_node_eligible(), which loops
over all previously processed slots (up to the current select index) and
reads res[j].orig_node to verify if the candidate was already selected.

This results in an uninitialized heap memory read during the pointer
comparison, which triggers a KMSAN violation. Because the garbage memory is
used only for equality comparison against active orig_node pointers, the
defect results in undefined behavior and a highly improbable false-positive
candidate match rather than a system crash or memory corruption.

// net/batman-adv/distributed-arp-table.c:182-206
static struct batadv_dat_candidate *
batadv_dat_select_candidates(struct batadv_priv *bat_priv, __be32 ip_dst)
{
	int select;
	< ... >
	struct batadv_dat_candidate *res;
	< ... >
	res = kmalloc(BATADV_DAT_CANDIDATES_NUM * sizeof(*res), GFP_ATOMIC);
	if (!res)
		return NULL;
	< ... >
	for (select = 0; select < BATADV_DAT_CANDIDATES_NUM; select++)
		batadv_choose_next_candidate(bat_priv, res, select, ip_key,
					     &last_max);

	return res;
}

// net/batman-adv/distributed-arp-table.c:114-162
static void batadv_choose_next_candidate(...)
{
	< ... >
	cands[select].type = BATADV_DAT_CANDIDATE_NOT_FOUND;

	for (i = 0; i < hash->size; i++) {
		< ... >
		hlist_for_each_entry_rcu(...) {
			< ... >
			if (!batadv_is_orig_node_eligible(cands, select, ...))
				continue;
			< ... >
		}
		< ... >
	}
	if (max_orig_node) {
		cands[select].type = BATADV_DAT_CANDIDATE_ORIG;
		cands[select].orig_node = max_orig_node;
		< ... >
	}
	< ... >
}

// net/batman-adv/distributed-arp-table.c:69-82
static bool batadv_is_orig_node_eligible(...)
{
	bool ret = false;
	int j;
	< ... >
	/* Check if this node has already been selected... */
	for (j = 0; j < select; j++)
		if (res[j].orig_node == candidate)
			break;
	< ... >
}

[-- Attachment #2: This is a digitally signed message part. --]
[-- Type: application/pgp-signature, Size: 228 bytes --]

      reply	other threads:[~2026-10-06 16:57 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-04  8:10 [PATCH batadv] batman-adv: dat: initialize orig_node of unfilled candidate slots Sven Eckelmann
2026-10-06 11:04 ` Linus Lüssing
2026-10-06 16:57   ` Sven Eckelmann [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=6321151.lOV4Wx5bFT@sven-desktop \
    --to=sven@narfation.org \
    --cc=b.a.t.m.a.n@lists.open-mesh.org \
    --cc=linus.luessing@c0d3.blue \
    --cc=sashiko-bot@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox