From: Antony Antony <antony.antony@secunet.com>
To: Antony Antony <antony.antony@secunet.com>,
Steffen Klassert <steffen.klassert@secunet.com>,
Herbert Xu <herbert@gondor.apana.org.au>,
"David S. Miller" <davem@davemloft.net>,
Eric Dumazet <edumazet@google.com>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
Simon Horman <horms@kernel.org>, David Ahern <dsahern@kernel.org>,
Jamal Hadi Salim <hadi@cyberus.ca>, Shuah Khan <shuah@kernel.org>
Cc: Sabrina Dubroca <sd@queasysnail.net>, <netdev@vger.kernel.org>,
Yan Yan <evitayan@google.com>,
Tobias Brunner <tobias@strongswan.org>,
Florian Westphal <fw@strlen.de>, <linux-doc@vger.kernel.org>,
<stable+noautosel@kernel.org>
Subject: [PATCH ipsec v5 3/9] xfrm: policy: reject mark with bits outside its mask on add
Date: Wed, 7 Oct 2026 11:35:00 +0200 [thread overview]
Message-ID: <migrate-state-fixes-v5-3-d9d3d794553d@secunet.com> (raw)
In-Reply-To: <migrate-state-fixes-v5-0-d9d3d794553d@secunet.com>
Same issue as states: an invalid mark/mask is silently truncated on
insert, so GETPOLICY and DELPOLICY can no longer find the policy by
id. Reject it instead.
The mark is no longer sanitized on policy insert.
Fixes: 0b91fda3a1f0 ("xfrm: Sanitize marks before insert")
Cc: <stable+noautosel@kernel.org> # avoid breaking existing userspace ABI
Signed-off-by: Antony Antony <antony.antony@secunet.com>
---
v4->v5: drop the now redundant mark sanitize in xfrm_policy_insert()
v3->v4: added this patch
---
net/xfrm/xfrm_policy.c | 3 ---
net/xfrm/xfrm_user.c | 3 +++
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/net/xfrm/xfrm_policy.c b/net/xfrm/xfrm_policy.c
index f6f40ba713d5..0f6fcea28bcd 100644
--- a/net/xfrm/xfrm_policy.c
+++ b/net/xfrm/xfrm_policy.c
@@ -1575,9 +1575,6 @@ int xfrm_policy_insert(int dir, struct xfrm_policy *policy, int excl)
struct xfrm_policy *delpol;
struct hlist_head *chain;
- /* Sanitize mark before store */
- policy->mark.v &= policy->mark.m;
-
spin_lock_bh(&net->xfrm.xfrm_policy_lock);
chain = policy_hash_bysel(net, &policy->selector, policy->family, dir);
if (chain)
diff --git a/net/xfrm/xfrm_user.c b/net/xfrm/xfrm_user.c
index 6b53373168b0..c1571c7a2315 100644
--- a/net/xfrm/xfrm_user.c
+++ b/net/xfrm/xfrm_user.c
@@ -2307,6 +2307,9 @@ static int xfrm_add_policy(struct sk_buff *skb, struct nlmsghdr *nlh,
if (err)
return err;
err = verify_sec_ctx_len(attrs, extack);
+ if (err)
+ return err;
+ err = verify_mark(attrs, extack);
if (err)
return err;
--
2.47.3
next prev parent reply other threads:[~2026-10-07 9:35 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-07 9:34 [PATCH ipsec v5 0/9] xfrm: state: exact mark/mask match for control-plane SA lookups Antony Antony
2026-10-07 9:34 ` [PATCH ipsec v5 1/9] xfrm: state: reject mark with bits outside its mask on add Antony Antony
2026-10-07 9:34 ` [PATCH ipsec v5 2/9] xfrm: state: reject mark with bits outside its mask on ALLOCSPI Antony Antony
2026-10-07 9:35 ` Antony Antony [this message]
2026-10-07 9:35 ` [PATCH ipsec v5 4/9] xfrm: state: exact mark/mask match for SPI-keyed control-plane SA lookups Antony Antony
2026-10-07 9:35 ` [PATCH ipsec v5 5/9] xfrm: fix use-after-free of migrated state in xfrm_do_migrate_state() Antony Antony
2026-10-07 9:35 ` [PATCH ipsec v5 6/9] xfrm: fix hw offload state leak on xfrm_do_migrate_state() error path Antony Antony
2026-10-07 9:35 ` [PATCH ipsec v5 7/9] xfrm: include mark in MIGRATE_STATE SA collision check Antony Antony
2026-10-07 9:35 ` [PATCH ipsec v5 8/9] xfrm: pass extack through to xfrm_init_replay() from xfrm_init_state() Antony Antony
2026-10-07 9:36 ` [PATCH ipsec v5 9/9] docs: xfrm: include mark in XFRM_MSG_MIGRATE_STATE EEXIST tuple Antony Antony
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=migrate-state-fixes-v5-3-d9d3d794553d@secunet.com \
--to=antony.antony@secunet.com \
--cc=davem@davemloft.net \
--cc=dsahern@kernel.org \
--cc=edumazet@google.com \
--cc=evitayan@google.com \
--cc=fw@strlen.de \
--cc=hadi@cyberus.ca \
--cc=herbert@gondor.apana.org.au \
--cc=horms@kernel.org \
--cc=kuba@kernel.org \
--cc=linux-doc@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=sd@queasysnail.net \
--cc=shuah@kernel.org \
--cc=stable+noautosel@kernel.org \
--cc=steffen.klassert@secunet.com \
--cc=tobias@strongswan.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox