netdev.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* [PATCH] netfilter: nfnetlink: fix uninitialized local variable
@ 2024-08-15  8:27 icejl
  2024-08-15  8:32 ` Pablo Neira Ayuso
  2024-08-15  9:04 ` Breno Leitao
  0 siblings, 2 replies; 7+ messages in thread
From: icejl @ 2024-08-15  8:27 UTC (permalink / raw)
  To: pablo, kadlec, davem, edumazet, kuba, pabeni
  Cc: netfilter-devel, coreteam, netdev, linux-kernel, icejl

In the nfnetlink_rcv_batch function, an uninitialized local variable
extack is used, which results in using random stack data as a pointer.
This pointer is then used to access the data it points to and return
it as the request status, leading to an information leak. If the stack
data happens to be an invalid pointer, it can cause a pointer access
exception, triggering a kernel crash.

Signed-off-by: icejl <icejl0001@gmail.com>
---
 net/netfilter/nfnetlink.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/net/netfilter/nfnetlink.c b/net/netfilter/nfnetlink.c
index 4abf660c7baf..b29b281f4b2c 100644
--- a/net/netfilter/nfnetlink.c
+++ b/net/netfilter/nfnetlink.c
@@ -427,6 +427,7 @@ static void nfnetlink_rcv_batch(struct sk_buff *skb, struct nlmsghdr *nlh,
 
 	nfnl_unlock(subsys_id);
 
+	memset(&extack, 0, sizeof(extack));
 	if (nlh->nlmsg_flags & NLM_F_ACK)
 		nfnl_err_add(&err_list, nlh, 0, &extack);
 
-- 
2.34.1


^ permalink raw reply related	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2024-08-15 10:03 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2024-08-15  8:27 [PATCH] netfilter: nfnetlink: fix uninitialized local variable icejl
2024-08-15  8:32 ` Pablo Neira Ayuso
2024-08-15  8:55   ` Pablo Neira Ayuso
2024-08-15  9:04 ` Breno Leitao
2024-08-15  9:32   ` Pablo Neira Ayuso
2024-08-15  9:55     ` Breno Leitao
2024-08-15 10:03       ` Pablo Neira Ayuso

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).