Netdev List
 help / color / mirror / Atom feed
* Re: [PATCH] wireguard: allowedips: prevent stack overflow without DEBUG
@ 2026-10-01  4:12 netdev-bot+sinfo
  0 siblings, 0 replies; 6+ messages in thread
From: netdev-bot+sinfo @ 2026-10-01  4:12 UTC (permalink / raw)
  To: quantumvoid
  Cc: wireguard@lists.zx2c4.com, Jason@zx2c4.com,
	netdev@vger.kernel.org

Hi!

This is an automated message. This series looks like a fix, but its
commit messages seem to be missing some information:

 - How the issue was discovered, e.g. hit in production, hit during
   development, syzbot report, manual code inspection, LLM or static
   analysis tool scan.

 - Whether the issue was actually triggered, or is only theoretical
   (e.g. found by code inspection). If it was triggered please include
   the symptoms, like the stack trace or error messages.

Please do not repost the series just to address the above. Instead,
reply to this email with the missing information, so that reviewers
can take it into account. If the series needs another revision for
other reasons, please include the information in the commit messages
then.

The evaluation is done by an LLM so it may be wrong, if you think
that is the case please reply and explain.

^ permalink raw reply	[flat|nested] 6+ messages in thread
* [PATCH] wireguard: allowedips: prevent stack overflow without DEBUG
@ 2026-10-01  4:09 quantumvoid
  2026-10-05  4:25 ` netdev-bot+sashiko
  0 siblings, 1 reply; 6+ messages in thread
From: quantumvoid @ 2026-10-01  4:09 UTC (permalink / raw)
  To: wireguard@lists.zx2c4.com; +Cc: Jason@zx2c4.com, netdev@vger.kernel.org

push_rcu() only bounds-checked the traversal stack when
DEBUG is defined. In production the check is compiled out,
leaving an unchecked stack[129] write.

Always check len >= MAX_ALLOWEDIPS_DEPTH and only gate the
WARN splat on DEBUG.

Signed-off-by: quantumvoid0 <quantumvoid0@proton.me>
---
 drivers/net/wireguard/allowedips.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/drivers/net/wireguard/allowedips.c b/drivers/net/wireguard/allowedips.c
index 5ece9ac..dc383f5 100644
--- a/drivers/net/wireguard/allowedips.c
+++ b/drivers/net/wireguard/allowedips.c
@@ -42,8 +42,10 @@ static void push_rcu(struct allowedips_node **stack,
 		     struct allowedips_node __rcu *p, unsigned int *len)
 {
 	if (rcu_access_pointer(p)) {
-		if (WARN_ON(IS_ENABLED(DEBUG) && *len >= MAX_ALLOWEDIPS_DEPTH))
+		if (unlikely(*len >= MAX_ALLOWEDIPS_DEPTH)) {
+			WARN_ON(IS_ENABLED(DEBUG));
 			return;
+		}
 		stack[(*len)++] = rcu_dereference_raw(p);
 	}
 }
--
2.55.0

^ permalink raw reply related	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2026-10-05 12:23 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-01  4:12 [PATCH] wireguard: allowedips: prevent stack overflow without DEBUG netdev-bot+sinfo
  -- strict thread matches above, loose matches on Subject: below --
2026-10-01  4:09 quantumvoid
2026-10-05  4:25 ` netdev-bot+sashiko
2026-10-05 12:13   ` quantumvoid0
2026-10-05 12:19     ` Jason A. Donenfeld
2026-10-05 12:23       ` quantumvoid0

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox