* [PATCH net] can: j1939: zero the reassembly buffer to avoid uninitialized slab leak
@ 2026-07-06 1:11 Xiang Mei
2026-08-12 23:57 ` Xiang Mei
0 siblings, 1 reply; 3+ messages in thread
From: Xiang Mei @ 2026-07-06 1:11 UTC (permalink / raw)
To: Robin van der Gracht, Oleksij Rempel, Oliver Hartkopp,
Marc Kleine-Budde, kernel
Cc: linux-can, linux-kernel, bestswngs, Xiang Mei
j1939_session_fresh_new() allocates the reassembly buffer with alloc_skb()
and exposes its whole data area via skb_put(skb, size) without zeroing it.
For non-ETP sessions j1939_xtp_rx_rts_session_new() sets pkt.total from an
attacker-controlled byte of the RTS/BAM frame (session->pkt.total =
dat[3]); a mismatch only warns and does not abort. A small pkt.total marks
the message complete after only a few bytes are copied, and
j1939_sk_recvmsg() delivers the full skb->len, leaking the untouched tail
of the buffer as uninitialized slab memory.
Zero the data area with skb_put_zero().
Fixes: 9d71dd0c7009 ("can: add support of SAE J1939 protocol")
Reported-by: Weiming Shi <bestswngs@gmail.com>
Signed-off-by: Xiang Mei <xmei5@asu.edu>
Assisted-by: Claude:claude-opus-4-8
---
net/can/j1939/transport.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/can/j1939/transport.c b/net/can/j1939/transport.c
index df93d57907da..2e062f7d277d 100644
--- a/net/can/j1939/transport.c
+++ b/net/can/j1939/transport.c
@@ -1568,7 +1568,7 @@ j1939_session *j1939_session_fresh_new(struct j1939_priv *priv,
}
/* alloc data area */
- skb_put(skb, size);
+ skb_put_zero(skb, size);
/* skb is recounted in j1939_session_new() */
return session;
}
--
2.43.0
^ permalink raw reply related [flat|nested] 3+ messages in thread* Re: [PATCH net] can: j1939: zero the reassembly buffer to avoid uninitialized slab leak
2026-07-06 1:11 [PATCH net] can: j1939: zero the reassembly buffer to avoid uninitialized slab leak Xiang Mei
@ 2026-08-12 23:57 ` Xiang Mei
2026-08-13 6:29 ` Oleksij Rempel
0 siblings, 1 reply; 3+ messages in thread
From: Xiang Mei @ 2026-08-12 23:57 UTC (permalink / raw)
To: Robin van der Gracht, Oleksij Rempel, Oliver Hartkopp,
Marc Kleine-Budde, kernel
Cc: linux-can, linux-kernel, bestswngs
Hi maintainers,
Just a reminder to avoid spending time on this. A recent commit fixes
this issue:
https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net.git/commit/?id=eb96c5890792
Xiang
On Sun, Jul 5, 2026 at 6:11 PM Xiang Mei <xmei5@asu.edu> wrote:
>
> j1939_session_fresh_new() allocates the reassembly buffer with alloc_skb()
> and exposes its whole data area via skb_put(skb, size) without zeroing it.
>
> For non-ETP sessions j1939_xtp_rx_rts_session_new() sets pkt.total from an
> attacker-controlled byte of the RTS/BAM frame (session->pkt.total =
> dat[3]); a mismatch only warns and does not abort. A small pkt.total marks
> the message complete after only a few bytes are copied, and
> j1939_sk_recvmsg() delivers the full skb->len, leaking the untouched tail
> of the buffer as uninitialized slab memory.
>
> Zero the data area with skb_put_zero().
>
> Fixes: 9d71dd0c7009 ("can: add support of SAE J1939 protocol")
> Reported-by: Weiming Shi <bestswngs@gmail.com>
> Signed-off-by: Xiang Mei <xmei5@asu.edu>
> Assisted-by: Claude:claude-opus-4-8
> ---
> net/can/j1939/transport.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/net/can/j1939/transport.c b/net/can/j1939/transport.c
> index df93d57907da..2e062f7d277d 100644
> --- a/net/can/j1939/transport.c
> +++ b/net/can/j1939/transport.c
> @@ -1568,7 +1568,7 @@ j1939_session *j1939_session_fresh_new(struct j1939_priv *priv,
> }
>
> /* alloc data area */
> - skb_put(skb, size);
> + skb_put_zero(skb, size);
> /* skb is recounted in j1939_session_new() */
> return session;
> }
> --
> 2.43.0
>
^ permalink raw reply [flat|nested] 3+ messages in thread* Re: [PATCH net] can: j1939: zero the reassembly buffer to avoid uninitialized slab leak
2026-08-12 23:57 ` Xiang Mei
@ 2026-08-13 6:29 ` Oleksij Rempel
0 siblings, 0 replies; 3+ messages in thread
From: Oleksij Rempel @ 2026-08-13 6:29 UTC (permalink / raw)
To: Xiang Mei
Cc: Robin van der Gracht, Oliver Hartkopp, Marc Kleine-Budde, kernel,
linux-can, linux-kernel, bestswngs
Hi Xiang Mei,
On Wed, Aug 12, 2026 at 04:57:45PM -0700, Xiang Mei wrote:
> Hi maintainers,
>
> Just a reminder to avoid spending time on this. A recent commit fixes
> this issue:
> https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net.git/commit/?id=eb96c5890792
Thank you for your feedback!
Best Regards,
Oleksij
--
Pengutronix e.K. | |
Steuerwalder Str. 21 | http://www.pengutronix.de/ |
31137 Hildesheim, Germany | Phone: +49-5121-206917-0 |
Amtsgericht Hildesheim, HRA 2686 | Fax: +49-5121-206917-5555 |
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-08-13 6:29 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-06 1:11 [PATCH net] can: j1939: zero the reassembly buffer to avoid uninitialized slab leak Xiang Mei
2026-08-12 23:57 ` Xiang Mei
2026-08-13 6:29 ` Oleksij Rempel
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox