netdev.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* [PATCH] net: Initialize ctx to avoid memory allocation error
@ 2025-03-13 19:54 Chenyuan Yang
  2025-03-13 20:10 ` Florian Westphal
  0 siblings, 1 reply; 7+ messages in thread
From: Chenyuan Yang @ 2025-03-13 19:54 UTC (permalink / raw)
  To: pablo, kadlec, davem, edumazet, kuba, pabeni, horms
  Cc: netfilter-devel, coreteam, netdev, linux-kernel, Chenyuan Yang

It is possible that ctx in nfqnl_build_packet_message() could be used
before it is properly initialize, which is only initialized
by nfqnl_get_sk_secctx().

This patch corrects this problem by initializing the lsmctx to a safe
value when it is declared.

This is similar to the commit 35fcac7a7c25
("audit: Initialize lsmctx to avoid memory allocation error").

Signed-off-by: Chenyuan Yang <chenyuan0y@gmail.com>
---
 net/netfilter/nfnetlink_queue.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/net/netfilter/nfnetlink_queue.c b/net/netfilter/nfnetlink_queue.c
index 5c913987901a..8b7b39d8a109 100644
--- a/net/netfilter/nfnetlink_queue.c
+++ b/net/netfilter/nfnetlink_queue.c
@@ -567,7 +567,7 @@ nfqnl_build_packet_message(struct net *net, struct nfqnl_instance *queue,
 	enum ip_conntrack_info ctinfo = 0;
 	const struct nfnl_ct_hook *nfnl_ct;
 	bool csum_verify;
-	struct lsm_context ctx;
+	struct lsm_context ctx = { NULL, 0, 0 };
 	int seclen = 0;
 	ktime_t tstamp;
 
-- 
2.34.1


^ permalink raw reply related	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2025-03-15 18:34 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2025-03-13 19:54 [PATCH] net: Initialize ctx to avoid memory allocation error Chenyuan Yang
2025-03-13 20:10 ` Florian Westphal
2025-03-14 16:41   ` Casey Schaufler
2025-03-14 16:47     ` Florian Westphal
2025-03-14 17:26       ` Casey Schaufler
2025-03-14 20:30         ` Florian Westphal
2025-03-15 18:34           ` Casey Schaufler

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).