mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH v2 net] net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD
@ 2026-07-22 12:28 Yehyeong Lee
  2026-07-23 18:10 ` patchwork-bot+netdevbpf
  0 siblings, 1 reply; 2+ messages in thread
From: Yehyeong Lee @ 2026-07-22 12:28 UTC (permalink / raw)
  To: nhorman, netdev
  Cc: davem, edumazet, kuba, pabeni, horms, idosch, jiri, linux-kernel,
	Yehyeong Lee

net_dm_packet_report_fill() and net_dm_hw_packet_report_fill() open code
the NET_DM_ATTR_PAYLOAD attribute to avoid zeroing the packet payload
before overwriting it with skb_copy_bits().

skb_put() reserves nla_total_size(payload_len), i.e. the header plus the
NLA_ALIGN() padding, but only payload_len bytes are copied in. When
payload_len is not a multiple of 4 the 1-3 padding bytes are never
initialized and are leaked to user space inside the netlink message.

KMSAN confirms the leak for the software path when the packet payload
length is not 4-byte aligned:

  BUG: KMSAN: kernel-infoleak in _copy_to_iter
   _copy_to_iter
   __skb_datagram_iter
   skb_copy_datagram_iter
   netlink_recvmsg
   sock_recvmsg
   __sys_recvfrom
  Uninit was created at:
   kmem_cache_alloc_node_noprof
   __alloc_skb
   net_dm_packet_work
  Bytes 173-175 of 176 are uninitialized

Use __nla_reserve(), which sets up the attribute header and zeroes the
padding, instead of open coding the attribute construction.

Fixes: ca30707dee2b ("drop_monitor: Add packet alert mode")
Fixes: 5e58109b1ea4 ("drop_monitor: Add support for packet alert mode for hardware drops")
Suggested-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: Yehyeong Lee <yhlee@isslab.korea.ac.kr>
---
v2: use __nla_reserve() instead of open coding the attribute (Eric Dumazet)
v1: https://lore.kernel.org/netdev/20260722104419.273358-1-yhlee@isslab.korea.ac.kr/

 net/core/drop_monitor.c | 8 ++------
 1 file changed, 2 insertions(+), 6 deletions(-)

diff --git a/net/core/drop_monitor.c b/net/core/drop_monitor.c
index 2bf3cab5e5..b4d1ff2829 100644
--- a/net/core/drop_monitor.c
+++ b/net/core/drop_monitor.c
@@ -671,9 +671,7 @@ static int net_dm_packet_report_fill(struct sk_buff *msg, struct sk_buff *skb,
 	if (nla_put_u16(msg, NET_DM_ATTR_PROTO, be16_to_cpu(skb->protocol)))
 		goto nla_put_failure;
 
-	attr = skb_put(msg, nla_total_size(payload_len));
-	attr->nla_type = NET_DM_ATTR_PAYLOAD;
-	attr->nla_len = nla_attr_size(payload_len);
+	attr = __nla_reserve(msg, NET_DM_ATTR_PAYLOAD, payload_len);
 	if (skb_copy_bits(skb, 0, nla_data(attr), payload_len))
 		goto nla_put_failure;
 
@@ -831,9 +829,7 @@ static int net_dm_hw_packet_report_fill(struct sk_buff *msg,
 	if (nla_put_u16(msg, NET_DM_ATTR_PROTO, be16_to_cpu(skb->protocol)))
 		goto nla_put_failure;
 
-	attr = skb_put(msg, nla_total_size(payload_len));
-	attr->nla_type = NET_DM_ATTR_PAYLOAD;
-	attr->nla_len = nla_attr_size(payload_len);
+	attr = __nla_reserve(msg, NET_DM_ATTR_PAYLOAD, payload_len);
 	if (skb_copy_bits(skb, 0, nla_data(attr), payload_len))
 		goto nla_put_failure;
 
-- 
2.43.0


^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: [PATCH v2 net] net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD
  2026-07-22 12:28 [PATCH v2 net] net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD Yehyeong Lee
@ 2026-07-23 18:10 ` patchwork-bot+netdevbpf
  0 siblings, 0 replies; 2+ messages in thread
From: patchwork-bot+netdevbpf @ 2026-07-23 18:10 UTC (permalink / raw)
  To: Yehyeong Lee
  Cc: nhorman, netdev, davem, edumazet, kuba, pabeni, horms, idosch,
	jiri, linux-kernel

Hello:

This patch was applied to netdev/net.git (main)
by Jakub Kicinski <kuba@kernel.org>:

On Wed, 22 Jul 2026 21:28:17 +0900 you wrote:
> net_dm_packet_report_fill() and net_dm_hw_packet_report_fill() open code
> the NET_DM_ATTR_PAYLOAD attribute to avoid zeroing the packet payload
> before overwriting it with skb_copy_bits().
> 
> skb_put() reserves nla_total_size(payload_len), i.e. the header plus the
> NLA_ALIGN() padding, but only payload_len bytes are copied in. When
> payload_len is not a multiple of 4 the 1-3 padding bytes are never
> initialized and are leaked to user space inside the netlink message.
> 
> [...]

Here is the summary with links:
  - [v2,net] net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD
    https://git.kernel.org/netdev/net/c/5e9c8baee032

You are awesome, thank you!
-- 
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html



^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-07-23 18:10 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-07-22 12:28 [PATCH v2 net] net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD Yehyeong Lee
2026-07-23 18:10 ` patchwork-bot+netdevbpf

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®