From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm1-f43.google.com (mail-wm1-f43.google.com [209.85.128.43]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3B3FB156F45 for ; Sun, 16 Aug 2026 07:33:13 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.43 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786865595; cv=none; b=D2su9+cxcwSqZCBBaZjRcmOCRlakiHBAxBKlgRYHrqwb/0ma4DWjC3yfkCewor6p2LVL/4qlnGs7dwzafSV3kdAyia7KEvtUvGE4VNZCj3QaLvd+U4MYAn7y6qcUKXr8AZS1YI8qILGz41Pkir+INkNym10XhkVXCEZkHVnBGkU= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786865595; c=relaxed/simple; bh=y6QcRCCfW4d495k95HuIQw2UVSsdUa46AUu5XwAig4Y=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=rNuxzbX9vEw2IQMuFloHsNcSWbGetPzFk+SLrns7pzcdgtFFh52toG+7EwZ99A8ZoXF6JqTHw3e57o03HMvLzZxdWbEhR96o0HpagCpkHgOa3DgEcU/118C6bKJui+7fyBbvKrYnsUV2C2riBW1MPF34AtSyve1MwtsjJngyiFQ= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=blackwall.org; spf=none smtp.mailfrom=blackwall.org; dkim=pass (2048-bit key) header.d=blackwall.org header.i=@blackwall.org header.b=TFuw2vXn; arc=none smtp.client-ip=209.85.128.43 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=blackwall.org Authentication-Results: smtp.subspace.kernel.org; spf=none smtp.mailfrom=blackwall.org Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=blackwall.org header.i=@blackwall.org header.b="TFuw2vXn" Received: by mail-wm1-f43.google.com with SMTP id 5b1f17b1804b1-4998b5a63e2so16454315e9.1 for ; Sun, 16 Aug 2026 00:33:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=blackwall.org; s=google; t=1786865591; x=1787470391; darn=vger.kernel.org; h=content-transfer-encoding:content-type:in-reply-to:from:references :cc:to:content-language:subject:user-agent:mime-version:date :message-id:from:to:cc:subject:date:message-id:reply-to:content-type; bh=V4Dxzk9SYkYwJWvs5z6wDXm/t0KB0vBdS9GjuR4ntoo=; b=TFuw2vXnxoOW3L4BrSg8lW59lHoNHG7x/vt3XCJpW+VlNy/kKOT/GErNa57tEr30HI cr0u5NBjN+0iVoegqWZSM9uO0Db5uoiaBgbtHWh6im09gZ2XFgiTFJdjSKRGg5hKZ031 0FZzUU/nIHCxAqYL49JobuXbBtiyMUDmc71aDt+BAGgupSeaUYxaXfl4ow5C9Zf59WU8 9fN7xI+RUQ3mO25xq/Id5/l8Yi4rzg8oIlwJeAVGibJIK09RMLguUw0zsDa0rzrQQAPs WhuEosuLmEi9JUgDp7zNv24MjQNEiuuYNHkle9qypNr81sjriXgNr530gbPPf77pSFg4 1vXw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786865591; x=1787470391; h=content-transfer-encoding:content-type:in-reply-to:from:references :cc:to:content-language:subject:user-agent:mime-version:date :message-id:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=V4Dxzk9SYkYwJWvs5z6wDXm/t0KB0vBdS9GjuR4ntoo=; b=LE/GYsCiZlhzp4uqttrDbwrgTr63liQv1iiSoLzi9GuaN9lC1CCuPGhB4z7qlcXDdZ 6ZUQfjCXg7yPyeruvEke+B53ib4KpjfFNTWe42epcgdro29I27LtNKeBMa9ZB7fh2Alr 15OK+lEFOkyY3byYk3F8hTC1xjIpUnMkP34l/BV0K4NMl15jCCi8ZzZE8rvxTVIf0IXm xPt0BtsfLMXPT7LUVnnbHz5IVXbV1G9rHUtjmNThK1NiqaYU3puRM+Y1xuQUX4dZ0KSt n7fJrVNtu5O9GhNECa4QK0JHik+tz/alymRLacfCfk8j+wDEK1jsVrxIL48+FUIJpMwo 2NVg== X-Forwarded-Encrypted: i=1; AHgh+RrtV5Uu6146hkFCr8ubNj5nNj1ZIe0JomgkmKJcwDKznXOHUMLeoG3IjsAFS/rmFcf+0Mavucg7w2ivk6s=@vger.kernel.org X-Gm-Message-State: AOJu0YzuxotC/bQOVTR8xkTUccYib0WDnc69UXEUJgNs9vppKIbOaY2r +ZP9HBmHmPkzbsfi/HW858e01LVosNiB1HdbGId4SzPQyg55FqgLoLBYqUbVpd2VhLw= X-Gm-Gg: AR+sD1250SUXDqj3V34ZSjMCJlVZI6xRg9/lvwp7ZMjPUkj0/UnGKZfCk1BS2is7mn1 EUQ4cZtGONEAvrFG+AWPzwAojGnJjGIQHc1kHCLx08HGnx5b0gWjLCOkbRl9CRNwywwj66hP25D hPqOSOSIURyUgCsCxVdt4rUaLrSD4mBxGnWZ+cWWrTwjRtUDP6BeQcZie87XHPPIQ+eDGhtV9GS hIwupegVNbUCGtPCJYLOEFnLqhPriSkidYHEbw/Lmjl87P+v45hbdfeQJydAawW4RSRKiWOY95+ tNYLpmuzLp62K4YJP1pEnfCbC/KbPv50cLHe1Onrh3mSTwSesqv5+WuYwnzSKe/LnJokZXrBzPc Yl1uy1tsocP52QVyPOj8zmNRig1jJP0QsqGkTf3EZNP+koo8BH7WVfkoBXPyLh86C3aBDDTytko lVACgEgBKHKC4ZEeq64FcVNxJWdrQSU2Pbm/bErVh8WMQNhz7j4Ea2zSAhzMCtPXXvu2E4Z4Mha VNca7u4yc1uPHG0wM+AXkHezjnE5BA= X-Received: by 2002:a05:600c:528d:b0:499:900c:9c69 with SMTP id 5b1f17b1804b1-499900c9e99mr124668415e9.9.1786865591344; Sun, 16 Aug 2026 00:33:11 -0700 (PDT) Received: from [192.168.0.161] (78-154-15-182.ip.btc-net.bg. [78.154.15.182]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49996188217sm53667815e9.13.2026.08.16.00.33.10 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Sun, 16 Aug 2026 00:33:10 -0700 (PDT) Message-ID: <0d917407-feaf-41c6-af7f-080aced09bf3@blackwall.org> Date: Sun, 16 Aug 2026 10:33:09 +0300 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH net] net: bridge: Reject descending VLAN tunnel ranges Content-Language: en-US, bg To: Ruoyu Wang , Ido Schimmel , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman Cc: bridge@lists.linux.dev, netdev@vger.kernel.org, linux-kernel@vger.kernel.org References: <20260814134053.1387275-1-ruoyuw560@gmail.com> From: Nikolay Aleksandrov In-Reply-To: <20260814134053.1387275-1-ruoyuw560@gmail.com> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit On 14/08/2026 16:40, Ruoyu Wang wrote: > A pair of descending VLAN and tunnel IDs can pass the tunnel range span > check. The VLAN subtraction produces a negative int, which is converted > to unsigned when compared with the u32 tunnel ID subtraction. It can > therefore equal the wrapped tunnel ID delta. > > The range loop then performs no iterations. Since the batched > notification handling added a post-loop error check, this leaves err > uninitialized and makes the request's return value unpredictable. > > Reject descending VLAN ranges before comparing the spans. Valid > ascending and single-entry ranges remain unchanged, while malformed > descending ranges consistently return -EINVAL. > > This issue was found by a static analysis checker and confirmed by > manual source review. > > Fixes: 94339443686b ("net: bridge: notify on vlan tunnel changes done via the old api") > Signed-off-by: Ruoyu Wang > --- > net/bridge/br_netlink_tunnel.c | 3 ++- > 1 file changed, 2 insertions(+), 1 deletion(-) > > diff --git a/net/bridge/br_netlink_tunnel.c b/net/bridge/br_netlink_tunnel.c > index 71a12da30004c..05f560eeb789c 100644 > --- a/net/bridge/br_netlink_tunnel.c > +++ b/net/bridge/br_netlink_tunnel.c > @@ -301,7 +301,8 @@ int br_process_vlan_tunnel_info(const struct net_bridge *br, > > if (!(tinfo_last->flags & BRIDGE_VLAN_INFO_RANGE_BEGIN)) > return -EINVAL; > - if ((tinfo_curr->vid - tinfo_last->vid) != > + if (tinfo_curr->vid < tinfo_last->vid || > + (tinfo_curr->vid - tinfo_last->vid) != > (tinfo_curr->tunid - tinfo_last->tunid)) > return -EINVAL; > t = tinfo_last->tunid; Acked-by: Nikolay Aleksandrov