From mboxrd@z Thu Jan 1 00:00:00 1970 From: Josh Poimboeuf Subject: Re: [PATCH] netlink: Fix spectre v1 gadget in netlink_create() Date: Tue, 31 Jul 2018 16:23:53 -0500 Message-ID: <20180731212353.kydep424ncpoht75@treble> References: <20180731211316.12971-1-jcline@redhat.com> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Cc: "David S . Miller" , netdev@vger.kernel.org, linux-kernel@vger.kernel.org To: Jeremy Cline Return-path: Content-Disposition: inline In-Reply-To: <20180731211316.12971-1-jcline@redhat.com> Sender: linux-kernel-owner@vger.kernel.org List-Id: netdev.vger.kernel.org On Tue, Jul 31, 2018 at 09:13:16PM +0000, Jeremy Cline wrote: > 'protocol' is a user-controlled value, so sanitize it after the bounds > check to avoid using it for speculative out-of-bounds access to arrays > indexed by it. > > This addresses the following accesses detected with the help of smatch: > > * net/netlink/af_netlink.c:654 __netlink_create() warn: potential > spectre issue 'nlk_cb_mutex_keys' [w] > > * net/netlink/af_netlink.c:654 __netlink_create() warn: potential > spectre issue 'nlk_cb_mutex_key_strings' [w] > > * net/netlink/af_netlink.c:685 netlink_create() warn: potential spectre > issue 'nl_table' [w] (local cap) > > Cc: Josh Poimboeuf > Signed-off-by: Jeremy Cline Reviewed-by: Josh Poimboeuf -- Josh