B.A.T.M.A.N Archive on lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH batadv] batman-adv: dat: initialize orig_node of unfilled candidate slots
@ 2026-10-04  8:10 Sven Eckelmann
  2026-10-06 11:04 ` Linus Lüssing
  0 siblings, 1 reply; 3+ messages in thread
From: Sven Eckelmann @ 2026-10-04  8:10 UTC (permalink / raw)
  To: b.a.t.m.a.n; +Cc: Sashiko, Sven Eckelmann

batadv_dat_select_candidates() allocates the candidate array without
zeroing it. batadv_choose_next_candidate() marks each slot as
BATADV_DAT_CANDIDATE_NOT_FOUND but only sets orig_node when an eligible
originator was found. In the following rounds,
batadv_is_orig_node_eligible() compares res[j].orig_node of all previous
slots against the evaluated originator. For slots without candidates, it
reads uninitialized memory.

The orig_node has to be cleared together with the
BATADV_DAT_CANDIDATE_NOT_FOUND type.

Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/bug/linux-b25d9aa4-10bb-427c-a145-ccaadc2a1bb9
Fixes: 34b3c3850e7d ("batman-adv: Distributed ARP Table - create DHT helper functions")
Signed-off-by: Sven Eckelmann <sven@narfation.org>
---
 net/batman-adv/distributed-arp-table.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/net/batman-adv/distributed-arp-table.c b/net/batman-adv/distributed-arp-table.c
index 74050bff..0260ed7e 100644
--- a/net/batman-adv/distributed-arp-table.c
+++ b/net/batman-adv/distributed-arp-table.c
@@ -653,6 +653,7 @@ static void batadv_choose_next_candidate(struct batadv_priv *bat_priv,
 	 * NOT_FOUND
 	 */
 	cands[select].type = BATADV_DAT_CANDIDATE_NOT_FOUND;
+	cands[select].orig_node = NULL;
 
 	/* iterate over the originator list and find the node with the closest
 	 * dat_address which has not been selected yet

---
base-commit: 4fa5cbac90fa7b8936779b4313debb3d89701c59
change-id: 20261004-dat-eligable-uninitialized-d8554210f36d

Best regards,
--  
Sven Eckelmann <sven@narfation.org>


^ permalink raw reply related	[flat|nested] 3+ messages in thread

* Re: [PATCH batadv] batman-adv: dat: initialize orig_node of unfilled candidate slots
  2026-10-04  8:10 [PATCH batadv] batman-adv: dat: initialize orig_node of unfilled candidate slots Sven Eckelmann
@ 2026-10-06 11:04 ` Linus Lüssing
  2026-10-06 16:57   ` Sven Eckelmann
  0 siblings, 1 reply; 3+ messages in thread
From: Linus Lüssing @ 2026-10-06 11:04 UTC (permalink / raw)
  To: Sven Eckelmann; +Cc: b.a.t.m.a.n, Sashiko

On Sun, Oct 04, 2026 at 10:10:06AM +0200, Sven Eckelmann wrote:
> batadv_dat_select_candidates() allocates the candidate array without
> zeroing it. batadv_choose_next_candidate() marks each slot as
> BATADV_DAT_CANDIDATE_NOT_FOUND but only sets orig_node when an eligible
> originator was found. In the following rounds,
> batadv_is_orig_node_eligible() compares res[j].orig_node of all previous
> slots against the evaluated originator. For slots without candidates, it
> reads uninitialized memory.
> 
> The orig_node has to be cleared together with the
> BATADV_DAT_CANDIDATE_NOT_FOUND type.

Acked-by: Linus Lüssing <linus.luessing@c0d3.blue>

(Though this issue seems very hard/unlikely to trigger? And even
then the consequences would be minor and temporary?)

(Also, I can't read the Sashiko link, I guess it's only accessible for
maintainers?)

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH batadv] batman-adv: dat: initialize orig_node of unfilled candidate slots
  2026-10-06 11:04 ` Linus Lüssing
@ 2026-10-06 16:57   ` Sven Eckelmann
  0 siblings, 0 replies; 3+ messages in thread
From: Sven Eckelmann @ 2026-10-06 16:57 UTC (permalink / raw)
  To: Linus Lüssing; +Cc: b.a.t.m.a.n, Sashiko

[-- Attachment #1: Type: text/plain, Size: 2996 bytes --]

On Tuesday, 6 October 2026 13:04:08 CEST Linus Lüssing wrote:
[...]
> (Also, I can't read the Sashiko link, I guess it's only accessible for
> maintainers?)

I had to login to the sashiko.dev to get access to the "Bugs" section. And 
even after login, I can only access the "BATMAN ADVANCED" subsystem. I have no 
idea how to make the report readable for everyone. But this is the text:

In the batman-adv Distributed ARP Table (DAT) selection process, if an
early candidate selection round fails to find an eligible node,
batadv_is_orig_node_eligible() reads uninitialized heap memory when
evaluating nodes during subsequent rounds.

The vulnerability stems from batadv_dat_select_candidates() allocating the
candidate array using kmalloc() without zeroing the memory. It then
iteratively calls batadv_choose_next_candidate() to fill each slot. If no
candidate is found during a given iteration, the slot's type is marked as
BATADV_DAT_CANDIDATE_NOT_FOUND, but its orig_node pointer remains
uninitialized. During the next iteration, batadv_choose_next_candidate()
iterates over nodes and calls batadv_is_orig_node_eligible(), which loops
over all previously processed slots (up to the current select index) and
reads res[j].orig_node to verify if the candidate was already selected.

This results in an uninitialized heap memory read during the pointer
comparison, which triggers a KMSAN violation. Because the garbage memory is
used only for equality comparison against active orig_node pointers, the
defect results in undefined behavior and a highly improbable false-positive
candidate match rather than a system crash or memory corruption.

// net/batman-adv/distributed-arp-table.c:182-206
static struct batadv_dat_candidate *
batadv_dat_select_candidates(struct batadv_priv *bat_priv, __be32 ip_dst)
{
	int select;
	< ... >
	struct batadv_dat_candidate *res;
	< ... >
	res = kmalloc(BATADV_DAT_CANDIDATES_NUM * sizeof(*res), GFP_ATOMIC);
	if (!res)
		return NULL;
	< ... >
	for (select = 0; select < BATADV_DAT_CANDIDATES_NUM; select++)
		batadv_choose_next_candidate(bat_priv, res, select, ip_key,
					     &last_max);

	return res;
}

// net/batman-adv/distributed-arp-table.c:114-162
static void batadv_choose_next_candidate(...)
{
	< ... >
	cands[select].type = BATADV_DAT_CANDIDATE_NOT_FOUND;

	for (i = 0; i < hash->size; i++) {
		< ... >
		hlist_for_each_entry_rcu(...) {
			< ... >
			if (!batadv_is_orig_node_eligible(cands, select, ...))
				continue;
			< ... >
		}
		< ... >
	}
	if (max_orig_node) {
		cands[select].type = BATADV_DAT_CANDIDATE_ORIG;
		cands[select].orig_node = max_orig_node;
		< ... >
	}
	< ... >
}

// net/batman-adv/distributed-arp-table.c:69-82
static bool batadv_is_orig_node_eligible(...)
{
	bool ret = false;
	int j;
	< ... >
	/* Check if this node has already been selected... */
	for (j = 0; j < select; j++)
		if (res[j].orig_node == candidate)
			break;
	< ... >
}

[-- Attachment #2: This is a digitally signed message part. --]
[-- Type: application/pgp-signature, Size: 228 bytes --]

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-10-06 16:57 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-04  8:10 [PATCH batadv] batman-adv: dat: initialize orig_node of unfilled candidate slots Sven Eckelmann
2026-10-06 11:04 ` Linus Lüssing
2026-10-06 16:57   ` Sven Eckelmann

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox