From: Simon Wunderlich <sw@simonwunderlich.de>
To: netdev@vger.kernel.org
Cc: "David S. Miller" <davem@davemloft.net>,
Eric Dumazet <edumazet@google.com>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
Simon Horman <horms@kernel.org>,
b.a.t.m.a.n@lists.open-mesh.org,
Sven Eckelmann <sven@narfation.org>,
stable@kernel.org, Simon Wunderlich <sw@simonwunderlich.de>
Subject: [PATCH net 08/14] batman-adv: tt: prevent TVLV entry number overflow
Date: Fri, 15 May 2026 11:55:33 +0200 [thread overview]
Message-ID: <20260515095540.325586-9-sw@simonwunderlich.de> (raw)
In-Reply-To: <20260515095540.325586-1-sw@simonwunderlich.de>
From: Sven Eckelmann <sven@narfation.org>
The helpers to prepare the buffers for the local and global TT based
replies are trying to sum up all TT entries which can be found for each
VLAN. In theory, this sum can be too big for an u16 and therefore overflow.
A too small buffer would then be allocated for the TVLV.
The too small buffer will be handled gracefully by
batadv_tt_tvlv_generate() and is not causing a buffer overflow - just a
truncated reply. But this overflow shouldn't have happened in the first and
the too small buffer should never have been allocated when an overflow was
detected.
Cc: stable@kernel.org
Fixes: 7ea7b4a14275 ("batman-adv: make the TT CRC logic VLAN specific")
Signed-off-by: Sven Eckelmann <sven@narfation.org>
Signed-off-by: Simon Wunderlich <sw@simonwunderlich.de>
---
net/batman-adv/translation-table.c | 20 +++++++++++++++++---
1 file changed, 17 insertions(+), 3 deletions(-)
diff --git a/net/batman-adv/translation-table.c b/net/batman-adv/translation-table.c
index 2259b241e0b56..9f6e67771ffa8 100644
--- a/net/batman-adv/translation-table.c
+++ b/net/batman-adv/translation-table.c
@@ -804,11 +804,18 @@ batadv_tt_prepare_tvlv_global_data(struct batadv_orig_node *orig_node,
u16 total_entries = 0;
u8 *tt_change_ptr;
int vlan_entries;
+ u16 sum_entries;
spin_lock_bh(&orig_node->vlan_list_lock);
hlist_for_each_entry(vlan, &orig_node->vlan_list, list) {
vlan_entries = atomic_read(&vlan->tt.num_entries);
- total_entries += vlan_entries;
+
+ if (check_add_overflow(vlan_entries, total_entries, &sum_entries)) {
+ *tt_len = 0;
+ goto out;
+ }
+
+ total_entries = sum_entries;
num_vlan++;
}
@@ -893,15 +900,22 @@ batadv_tt_prepare_tvlv_local_data(struct batadv_priv *bat_priv,
struct batadv_meshif_vlan *vlan;
size_t change_offset;
u16 num_vlan = 0;
- u16 vlan_entries = 0;
u16 total_entries = 0;
u16 tvlv_len;
u8 *tt_change_ptr;
+ int vlan_entries;
+ u16 sum_entries;
spin_lock_bh(&bat_priv->meshif_vlan_list_lock);
hlist_for_each_entry(vlan, &bat_priv->meshif_vlan_list, list) {
vlan_entries = atomic_read(&vlan->tt.num_entries);
- total_entries += vlan_entries;
+
+ if (check_add_overflow(vlan_entries, total_entries, &sum_entries)) {
+ tvlv_len = 0;
+ goto out;
+ }
+
+ total_entries = sum_entries;
num_vlan++;
}
--
2.47.3
next prev parent reply other threads:[~2026-05-15 9:55 UTC|newest]
Thread overview: 15+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-05-15 9:55 [PATCH net 00/14] pull request: batman-adv 2026-05-15 Simon Wunderlich
2026-05-15 9:55 ` [PATCH net 01/14] batman-adv: fix tp_meter counter underflow during shutdown Simon Wunderlich
2026-05-15 9:55 ` [PATCH net 02/14] batman-adv: tp_meter: fix tp_vars reference leak in receiver shutdown Simon Wunderlich
2026-05-15 9:55 ` [PATCH net 03/14] batman-adv: tt: reject oversized local TVLV buffers Simon Wunderlich
2026-05-15 9:55 ` [PATCH net 04/14] batman-adv: tt: fix negative tt_buff_len Simon Wunderlich
2026-05-15 9:55 ` [PATCH net 05/14] batman-adv: tt: fix negative last_changeset_len Simon Wunderlich
2026-05-15 9:55 ` [PATCH net 06/14] batman-adv: tt: fix TOCTOU race for reported vlans Simon Wunderlich
2026-05-15 9:55 ` [PATCH net 07/14] batman-adv: tt: avoid empty VLAN responses Simon Wunderlich
2026-05-15 9:55 ` Simon Wunderlich [this message]
2026-05-15 9:55 ` [PATCH net 09/14] batman-adv: fix fragment reassembly length accounting Simon Wunderlich
2026-05-15 9:55 ` [PATCH net 10/14] batman-adv: clear current gateway during teardown Simon Wunderlich
2026-05-15 9:55 ` [PATCH net 11/14] batman-adv: dat: handle forward allocation error Simon Wunderlich
2026-05-15 9:55 ` [PATCH net 12/14] batman-adv: tp_meter: avoid use of uninit sender vars Simon Wunderlich
2026-05-15 9:55 ` [PATCH net 13/14] batman-adv: frag: disallow unicast fragment in fragment Simon Wunderlich
2026-05-15 9:55 ` [PATCH net 14/14] batman-adv: tp_meter: directly shut down timer on cleanup Simon Wunderlich
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260515095540.325586-9-sw@simonwunderlich.de \
--to=sw@simonwunderlich.de \
--cc=b.a.t.m.a.n@lists.open-mesh.org \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=horms@kernel.org \
--cc=kuba@kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=stable@kernel.org \
--cc=sven@narfation.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox