* [PATCH batadv] batman-adv: dat: initialize orig_node of unfilled candidate slots
@ 2026-10-04 8:10 Sven Eckelmann
2026-10-06 11:04 ` Linus Lüssing
0 siblings, 1 reply; 3+ messages in thread
From: Sven Eckelmann @ 2026-10-04 8:10 UTC (permalink / raw)
To: b.a.t.m.a.n; +Cc: Sashiko, Sven Eckelmann
batadv_dat_select_candidates() allocates the candidate array without
zeroing it. batadv_choose_next_candidate() marks each slot as
BATADV_DAT_CANDIDATE_NOT_FOUND but only sets orig_node when an eligible
originator was found. In the following rounds,
batadv_is_orig_node_eligible() compares res[j].orig_node of all previous
slots against the evaluated originator. For slots without candidates, it
reads uninitialized memory.
The orig_node has to be cleared together with the
BATADV_DAT_CANDIDATE_NOT_FOUND type.
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/bug/linux-b25d9aa4-10bb-427c-a145-ccaadc2a1bb9
Fixes: 34b3c3850e7d ("batman-adv: Distributed ARP Table - create DHT helper functions")
Signed-off-by: Sven Eckelmann <sven@narfation.org>
---
net/batman-adv/distributed-arp-table.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/net/batman-adv/distributed-arp-table.c b/net/batman-adv/distributed-arp-table.c
index 74050bff..0260ed7e 100644
--- a/net/batman-adv/distributed-arp-table.c
+++ b/net/batman-adv/distributed-arp-table.c
@@ -653,6 +653,7 @@ static void batadv_choose_next_candidate(struct batadv_priv *bat_priv,
* NOT_FOUND
*/
cands[select].type = BATADV_DAT_CANDIDATE_NOT_FOUND;
+ cands[select].orig_node = NULL;
/* iterate over the originator list and find the node with the closest
* dat_address which has not been selected yet
---
base-commit: 4fa5cbac90fa7b8936779b4313debb3d89701c59
change-id: 20261004-dat-eligable-uninitialized-d8554210f36d
Best regards,
--
Sven Eckelmann <sven@narfation.org>
^ permalink raw reply related [flat|nested] 3+ messages in thread* Re: [PATCH batadv] batman-adv: dat: initialize orig_node of unfilled candidate slots 2026-10-04 8:10 [PATCH batadv] batman-adv: dat: initialize orig_node of unfilled candidate slots Sven Eckelmann @ 2026-10-06 11:04 ` Linus Lüssing 2026-10-06 16:57 ` Sven Eckelmann 0 siblings, 1 reply; 3+ messages in thread From: Linus Lüssing @ 2026-10-06 11:04 UTC (permalink / raw) To: Sven Eckelmann; +Cc: b.a.t.m.a.n, Sashiko On Sun, Oct 04, 2026 at 10:10:06AM +0200, Sven Eckelmann wrote: > batadv_dat_select_candidates() allocates the candidate array without > zeroing it. batadv_choose_next_candidate() marks each slot as > BATADV_DAT_CANDIDATE_NOT_FOUND but only sets orig_node when an eligible > originator was found. In the following rounds, > batadv_is_orig_node_eligible() compares res[j].orig_node of all previous > slots against the evaluated originator. For slots without candidates, it > reads uninitialized memory. > > The orig_node has to be cleared together with the > BATADV_DAT_CANDIDATE_NOT_FOUND type. Acked-by: Linus Lüssing <linus.luessing@c0d3.blue> (Though this issue seems very hard/unlikely to trigger? And even then the consequences would be minor and temporary?) (Also, I can't read the Sashiko link, I guess it's only accessible for maintainers?) ^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH batadv] batman-adv: dat: initialize orig_node of unfilled candidate slots 2026-10-06 11:04 ` Linus Lüssing @ 2026-10-06 16:57 ` Sven Eckelmann 0 siblings, 0 replies; 3+ messages in thread From: Sven Eckelmann @ 2026-10-06 16:57 UTC (permalink / raw) To: Linus Lüssing; +Cc: b.a.t.m.a.n, Sashiko [-- Attachment #1: Type: text/plain, Size: 2996 bytes --] On Tuesday, 6 October 2026 13:04:08 CEST Linus Lüssing wrote: [...] > (Also, I can't read the Sashiko link, I guess it's only accessible for > maintainers?) I had to login to the sashiko.dev to get access to the "Bugs" section. And even after login, I can only access the "BATMAN ADVANCED" subsystem. I have no idea how to make the report readable for everyone. But this is the text: In the batman-adv Distributed ARP Table (DAT) selection process, if an early candidate selection round fails to find an eligible node, batadv_is_orig_node_eligible() reads uninitialized heap memory when evaluating nodes during subsequent rounds. The vulnerability stems from batadv_dat_select_candidates() allocating the candidate array using kmalloc() without zeroing the memory. It then iteratively calls batadv_choose_next_candidate() to fill each slot. If no candidate is found during a given iteration, the slot's type is marked as BATADV_DAT_CANDIDATE_NOT_FOUND, but its orig_node pointer remains uninitialized. During the next iteration, batadv_choose_next_candidate() iterates over nodes and calls batadv_is_orig_node_eligible(), which loops over all previously processed slots (up to the current select index) and reads res[j].orig_node to verify if the candidate was already selected. This results in an uninitialized heap memory read during the pointer comparison, which triggers a KMSAN violation. Because the garbage memory is used only for equality comparison against active orig_node pointers, the defect results in undefined behavior and a highly improbable false-positive candidate match rather than a system crash or memory corruption. // net/batman-adv/distributed-arp-table.c:182-206 static struct batadv_dat_candidate * batadv_dat_select_candidates(struct batadv_priv *bat_priv, __be32 ip_dst) { int select; < ... > struct batadv_dat_candidate *res; < ... > res = kmalloc(BATADV_DAT_CANDIDATES_NUM * sizeof(*res), GFP_ATOMIC); if (!res) return NULL; < ... > for (select = 0; select < BATADV_DAT_CANDIDATES_NUM; select++) batadv_choose_next_candidate(bat_priv, res, select, ip_key, &last_max); return res; } // net/batman-adv/distributed-arp-table.c:114-162 static void batadv_choose_next_candidate(...) { < ... > cands[select].type = BATADV_DAT_CANDIDATE_NOT_FOUND; for (i = 0; i < hash->size; i++) { < ... > hlist_for_each_entry_rcu(...) { < ... > if (!batadv_is_orig_node_eligible(cands, select, ...)) continue; < ... > } < ... > } if (max_orig_node) { cands[select].type = BATADV_DAT_CANDIDATE_ORIG; cands[select].orig_node = max_orig_node; < ... > } < ... > } // net/batman-adv/distributed-arp-table.c:69-82 static bool batadv_is_orig_node_eligible(...) { bool ret = false; int j; < ... > /* Check if this node has already been selected... */ for (j = 0; j < select; j++) if (res[j].orig_node == candidate) break; < ... > } [-- Attachment #2: This is a digitally signed message part. --] [-- Type: application/pgp-signature, Size: 228 bytes --] ^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-10-06 16:57 UTC | newest] Thread overview: 3+ messages (download: mbox.gz follow: Atom feed -- links below jump to the message on this page -- 2026-10-04 8:10 [PATCH batadv] batman-adv: dat: initialize orig_node of unfilled candidate slots Sven Eckelmann 2026-10-06 11:04 ` Linus Lüssing 2026-10-06 16:57 ` Sven Eckelmann
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox