* [PATCH] xfrm: zero-initialise km_event in replay-notify to stop stack disclosure
@ 2026-09-30 9:31 Shubham Antil
2026-09-30 9:34 ` netdev-bot+sinfo
0 siblings, 1 reply; 2+ messages in thread
From: Shubham Antil @ 2026-09-30 9:31 UTC (permalink / raw)
To: Steffen Klassert, Herbert Xu, David S . Miller
Cc: Eric Dumazet, Jakub Kicinski, Paolo Abeni, Simon Horman, netdev,
linux-kernel, Shubham Antil, Giovanni Vignone
xfrm_replay_notify(), xfrm_replay_notify_bmp() and
xfrm_replay_notify_esn() declare a struct km_event on the stack and
initialise only its .event and .data.aevent fields, leaving .seq and
.portid uninitialised. build_aevent() copies those two fields into the
XFRM_MSG_NEWAE netlink message header via
nlmsg_put(skb, c->portid, c->seq, ...), and the message is multicast to
the XFRMNLGRP_AEVENTS group, so two dwords of uninitialised kernel stack
are sent to group listeners on each replay event.
The request-driven paths set these header fields from the requester
(xfrm_get_ae() / xfrm_new_ae()); only the kernel-originated replay path
leaves them uninitialised. Zero-initialise the event so the header
fields are sent as 0, the correct value for a kernel-originated
notification.
Reported-by: Giovanni Vignone <gio@octane.security>
Assisted-by: LLM
Signed-off-by: Shubham Antil <shubham@octane.security>
---
net/xfrm/xfrm_replay.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/net/xfrm/xfrm_replay.c b/net/xfrm/xfrm_replay.c
index dbdf8a39df..9394953247 100644
--- a/net/xfrm/xfrm_replay.c
+++ b/net/xfrm/xfrm_replay.c
@@ -40,7 +40,7 @@ static void xfrm_replay_notify_esn(struct xfrm_state *x, int event);
void xfrm_replay_notify(struct xfrm_state *x, int event)
{
- struct km_event c;
+ struct km_event c = {};
/* we send notify messages in case
* 1. we updated on of the sequence numbers, and the seqno difference
* is at least x->replay_maxdiff, in this case we also update the
@@ -304,7 +304,7 @@ static void xfrm_replay_advance_bmp(struct xfrm_state *x, __be32 net_seq)
static void xfrm_replay_notify_bmp(struct xfrm_state *x, int event)
{
- struct km_event c;
+ struct km_event c = {};
struct xfrm_replay_state_esn *replay_esn = x->replay_esn;
struct xfrm_replay_state_esn *preplay_esn = x->preplay_esn;
@@ -356,7 +356,7 @@ static void xfrm_replay_notify_bmp(struct xfrm_state *x, int event)
static void xfrm_replay_notify_esn(struct xfrm_state *x, int event)
{
u32 seq_diff, oseq_diff;
- struct km_event c;
+ struct km_event c = {};
struct xfrm_replay_state_esn *replay_esn = x->replay_esn;
struct xfrm_replay_state_esn *preplay_esn = x->preplay_esn;
--
2.43.0
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: [PATCH] xfrm: zero-initialise km_event in replay-notify to stop stack disclosure
2026-09-30 9:31 [PATCH] xfrm: zero-initialise km_event in replay-notify to stop stack disclosure Shubham Antil
@ 2026-09-30 9:34 ` netdev-bot+sinfo
0 siblings, 0 replies; 2+ messages in thread
From: netdev-bot+sinfo @ 2026-09-30 9:34 UTC (permalink / raw)
To: Shubham Antil
Cc: Steffen Klassert, Herbert Xu, David S . Miller, Eric Dumazet,
Jakub Kicinski, Paolo Abeni, Simon Horman, netdev, linux-kernel,
Giovanni Vignone
Hi!
This is an automated message. This series looks like a fix, but its
commit messages seem to be missing some information:
- Whether the issue was actually triggered, or is only theoretical
(e.g. found by code inspection). If it was triggered please include
the symptoms, like the stack trace or error messages.
Please do not repost the series just to address the above. Instead,
reply to this email with the missing information, so that reviewers
can take it into account. If the series needs another revision for
other reasons, please include the information in the commit messages
then.
The evaluation is done by an LLM so it may be wrong, if you think
that is the case please reply and explain.
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-09-30 9:34 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-30 9:31 [PATCH] xfrm: zero-initialise km_event in replay-notify to stop stack disclosure Shubham Antil
2026-09-30 9:34 ` netdev-bot+sinfo
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®