From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 99BCE448D11; Wed, 23 Sep 2026 14:42:53 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790174574; cv=none; b=ZD8jzb23mxXaHgUHIYQAcwgn4cof9/OqzvCVtYdDx1ud4j0IF2yNRDgluhkPw5gZex7f8ulBlU5NDYcPCmHNqLq8VrqGroJYAqxaCaJ62lvHoj30OoPMlkwZxJ6OuLHlmIqEgfBWCVb364GHfCznx0WoGxpSi5GAPbQ9FU3DbGo= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790174574; c=relaxed/simple; bh=Nye3BAsnoeyzhnvPJGZWVinoyvp3l6oZJWexNeroqCs=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=TFVT7cTxpx5xlSMAo1KmUVyW50Z1RAMB0vX26nM1zo2aZn8B/Ey1bqoCFofDkL3bPi9T+5JiIs1SbqNlhP4r90hJVRdnkWGY9pSTks/zNbnvMDpZaW+eTPUDHSqXwIAUu3oyU9X21yxH6ybz5rxEW3TAQ+8jroRyQqifqZKkJHo= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=C9F09nM6; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="C9F09nM6" Received: by smtp.kernel.org (Postfix) with ESMTPSA id B93741F00893; Wed, 23 Sep 2026 14:42:52 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790174573; bh=FSKRJfpKJ23nPCk4mE2tyVpV/Xk17K4r7begdgevmnA=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=C9F09nM6qFQkaXqRfTFxevpUeNQ/2ApXBqhDhDOqgvS1MziYklbqf62P4C/C6RtWQ bVinxkyHT4G/dVIY7aGIBnbpWYJKNERnO6JHCl1pTAdA0RciVW4gin7nQQkqQm3sJm hbCci3rh8xwRwhvMrYK3QX6kWP4msr4yTXomnGYM= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Eric Dumazet , Hangbin Liu , Jakub Kicinski , Sasha Levin Subject: [PATCH 6.18 158/398] drop_monitor: fix out-of-bounds write in reset_per_cpu_data() Date: Wed, 23 Sep 2026 16:03:52 +0200 Message-ID: <20260923140647.530438916@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260923140643.441954610@linuxfoundation.org> References: <20260923140643.441954610@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 6.18-stable review patch. If anyone has any objections, please let me know. ------------------ From: Eric Dumazet [ Upstream commit 439f392084f8f7f59ab9d47a9579185accefe1d8 ] In reset_per_cpu_data(), al is computed as: al = sizeof(struct net_dm_alert_msg); al += dm_hit_limit * sizeof(struct net_dm_drop_point); al += sizeof(struct nlattr); skb = genlmsg_new(al, GFP_KERNEL); ... nla = nla_reserve(skb, NLA_UNSPEC, sizeof(struct net_dm_alert_msg)); ... msg = nla_data(nla); memset(msg, 0, al); Because al includes sizeof(struct nlattr) (the 4-byte attribute header), genlmsg_new() allocates al bytes of tailroom starting at nla. However, msg points to nla_data(nla), which is located sizeof(struct nlattr) bytes past nla. Calling memset(msg, 0, al) therefore writes al bytes starting from msg, exceeding the allocated buffer by sizeof(struct nlattr) (4 bytes) and corrupting skb_shared_info. Fix this by letting al represent only the payload length, allocating the skb with genlmsg_new(nla_total_size(al), GFP_KERNEL), and zeroing al bytes from msg. Fixes: 683703a26e46 ("drop_monitor: Update netlink protocol to include netlink attribute header in alert message") Signed-off-by: Eric Dumazet Reviewed-by: Hangbin Liu Link: https://patch.msgid.link/20260910204612.3762015-5-edumazet@google.com Signed-off-by: Jakub Kicinski Signed-off-by: Sasha Levin --- net/core/drop_monitor.c | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/net/core/drop_monitor.c b/net/core/drop_monitor.c index b56da4d8c879e..996ae451af628 100644 --- a/net/core/drop_monitor.c +++ b/net/core/drop_monitor.c @@ -141,9 +141,8 @@ static struct sk_buff *reset_per_cpu_data(struct per_cpu_dm_data *data) al = sizeof(struct net_dm_alert_msg); al += dm_hit_limit * sizeof(struct net_dm_drop_point); - al += sizeof(struct nlattr); - skb = genlmsg_new(al, GFP_KERNEL); + skb = genlmsg_new(nla_total_size(al), GFP_KERNEL); if (!skb) goto err; -- 2.53.0