From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-yw1-f169.google.com (mail-yw1-f169.google.com [209.85.128.169]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D114548A8BA for ; Wed, 29 Jul 2026 13:19:51 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.169 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785331194; cv=none; b=dHdhu3BnKm9bzV10V2zvYpX95q/UNGFmRNWoK0GbxtZZ2oSs5iK2Ti70B9s/ugN2kaH4FanO4FKNWhUXey+WH/g/MlhSIbGb0NH4cF4oYIjMezPXdN5BrylsYOEAYPlwu+Y1YvqocwiWXbvVWO4E8wcAuf5CaMqHvGab5xneybE= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785331194; c=relaxed/simple; bh=kdlhdT6qgk713ttnMT/RjwDbI68wlDahWZC3PMz1mLk=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=oFcJGRpu0p8u5ChVwlurS5NKgTNE+Uddzpu78thr2gBsC/k6jGvHmEOAGDJmFk2L3V+f6387YWie+Bxh6xK03rYA5sxXA10VusySw+ozRReOwLtb2rcJRLwdnAWELguHx9WCansAYfnLq8vKAMnHLg7456SqTdSllnnBuvvUzGA= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=xbow.com; spf=pass smtp.mailfrom=xbow.com; dkim=pass (2048-bit key) header.d=xbow.com header.i=@xbow.com header.b=MWB+OZSJ; arc=none smtp.client-ip=209.85.128.169 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=xbow.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=xbow.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=xbow.com header.i=@xbow.com header.b="MWB+OZSJ" Received: by mail-yw1-f169.google.com with SMTP id 00721157ae682-80e2cfe6918so11962327b3.0 for ; Wed, 29 Jul 2026 06:19:51 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=xbow.com; s=google; t=1785331191; x=1785935991; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=KMXrirPZU7fXTxWoE1e8bDQ+DkmRVCXCwha59Dx6pk0=; b=MWB+OZSJjDeAYCCmKe27IhSRTrKqz60HJKDZ+e+GZ3O91T3PUqvIlxmgzDYip0PXVj XZRhAQd3oWlA+9K8v5vzo5OnHTtNbOs7Ixp53cV8zRNyL1pTvehVoPNMGWgib81KB/1O 4bAgEoGrPLVX+0YqbPB/m2OXHEqU9LOMGrp/0TygWb14bjqsouaxtOGEklNyzjG7CGIt ISVSQKJCR8ROa3fNVdtQVw+/yptlgapMtZZOXmos5MVI5L8ih3WoEkDkwGVK32r8h1Gu gIn5IZp7nLVA6+rMT+6QWR3wQq4HFJY05oaPAa+7Oo2G4tWmlepB8EIUaALvTZWQkFj/ rXUQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785331191; x=1785935991; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=KMXrirPZU7fXTxWoE1e8bDQ+DkmRVCXCwha59Dx6pk0=; b=m/EdK1nTReUt1WZPrpCWqgR0fsA8HCMh5P2wE7iVo0PWBQ72mLDwrYzh4eem/2sRzM 4po0ETDkgeb50wYuwRoNhvE0lpQSc/Icc/OiIiEJEeT2xE2b5yZOhgxDAZa8N3YCcIAp acn1r0yQ4Q3KoBVFtNPFWdz97m3eRf4uTOI1L0ar1J5+o1wXw0m47KdfkYtGqkT3qdD/ b3LYgLXs+Dox5R16Z9joX3Qrp2oZgW/VTP5+l4b4QONZ0YmzUGlp0BHlxuTucBg3ppa5 H1veS6F4HHRoBMJUbp3yzAComNaoc/zvrpEd+twZ5TXuSh1VW/VSY0jhbM8get2QQMmP lnQg== X-Forwarded-Encrypted: i=1; AHgh+RrAPg+pZUTFu39h4g5+8T3vC1nZnJ3c3bqu/g4pxkit9SeU8jgFD7RbIjiD18lTiVqiWZD6b3lHE6eWCIY=@vger.kernel.org X-Gm-Message-State: AOJu0YyBz2l4DwJoeFgNEsF7X+WlwLN0IHfPUI8WjPnjBRdxWtmf+BmQ fIjZDXxRP9joLmqCpFdakSCTJpqePIS26pQHGkVQ1i2KEbRkIwooOmGvGzpyTJNTeIM= X-Gm-Gg: AR+sD108EX1T2IYqUQ2/NKu0ktiSrOHuV1JQUqAF7MEKf3DXDJwoYZwdffPl8HlkjXF BzqeYfMQRdTbvCne1Z3+6RJp2UkmfjcrkafmRlwculp/wkisr6KazTi6h1NDlCYTdL4TIlYRjm9 yfWC28mqybAgTc0Om0YZ68HQ8VcO7SimHq9jRtBagZXLmuX1sd44ozP6Jhg+c8d0Z0ZezRg0hgi prHxQIynDoV9UjRXClCmYUaYUPjfCRnTZqKRrW2njwCRNotdNti/tHJkgOz8uUlZFBQMBFJzwKT qhuBg4LmibODuTR3VDzJQhZvqTLqWHNW1sLq+sjbwTZpS/61bbIV7zpq38aEtquMW/czMmzUlI8 706ZL8DiE70LN/8y84lFVr+swSuAPd+lZiQ7a2c5gjtIqCkgmupGrJnOhylYfoIj5HRPRA16J/E tKxQCjEd23FbPir3Cm8uIsdxxlywicpOpb9g5LkJjnJgXDVSagSA9rFLFnL+/Kc1YQr0vg+CEoJ oOOaNt6FWbNoNFz2dc4TZbUHb1whsN9gW4EiHaXQTZVdg8S8/K9hBhRCS2CGlM4UectGVbLAKm3 q9WdOIxREoTRNmSy07JRJvmLdn7Sxg== X-Received: by 2002:a05:690c:62c7:b0:814:5312:47bb with SMTP id 00721157ae682-81f993f145fmr33494437b3.69.1785331190331; Wed, 29 Jul 2026 06:19:50 -0700 (PDT) Received: from buildmachine.tailf331da.ts.net (ec2-3-14-143-233.us-east-2.compute.amazonaws.com. [3.14.143.233]) by smtp.gmail.com with ESMTPSA id 00721157ae682-81fa275691asm17653907b3.4.2026.07.29.06.19.45 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Wed, 29 Jul 2026 06:19:50 -0700 (PDT) From: Baul Lee To: netdev@vger.kernel.org, bridge@lists.linux.dev, linux-kernel@vger.kernel.org Cc: Nikolay Aleksandrov , Ido Schimmel , Andrew Lunn , "David S . Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , stable@vger.kernel.org, Baul Lee Subject: [PATCH net v2] net: bridge: mrp: fix uninitialised bytes on the wire Date: Wed, 29 Jul 2026 22:19:41 +0900 Message-ID: <20260729131941.10254-1-baul.lee@xbow.com> X-Mailer: git-send-email 2.50.1 In-Reply-To: <20260726062518.43774-1-baul.lee@xbow.com> References: <20260726062518.43774-1-baul.lee@xbow.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit br_mrp_alloc_test_skb() builds MRP test frames on an skb from dev_alloc_skb(), which does not clear the linear data area. On the MRA ring-role branch the sub-option TLV header is appended with sub_tlv = skb_put(skb, sizeof(*sub_tlv)); sub_tlv->type = BR_MRP_SUB_TLV_HEADER_TEST_AUTO_MGR; so sub_tlv->length is never written, and the two trailing alignment bytes are appended with a bare skb_put() that does not clear them either. The neighbouring oui and sub_opt regions are explicitly zeroed, so three uninitialised bytes are left in every MRA MRP_Test frame that goes out. Put the sub-option TLV header and the alignment padding in a single skb_put_zero(), which clears both. The AUTO_MGR sub-TLV carries no payload, so the zeroed length field is already the value it should have. Fixes: f7458934b079 ("net: bridge: mrp: Update the Test frames for MRA") Suggested-by: Nikolay Aleksandrov Cc: stable@vger.kernel.org Signed-off-by: Baul Lee --- v2: - fold the alignment padding into a single skb_put_zero() for the sub-option TLV header, dropping the explicit length assignment and the second skb_put() (Nikolay Aleksandrov) - drop the paragraph about observing the leak, and the Reported-by tags Link to v1: https://lore.kernel.org/netdev/20260726062518.43774-1-baul.lee@xbow.com/ net/bridge/br_mrp.c | 6 ++---- 1 file changed, 2 insertions(+), 4 deletions(-) diff --git a/net/bridge/br_mrp.c b/net/bridge/br_mrp.c index 179d2470b..ef16d0703 100644 --- a/net/bridge/br_mrp.c +++ b/net/bridge/br_mrp.c @@ -224,11 +224,9 @@ static struct sk_buff *br_mrp_alloc_test_skb(struct br_mrp *mrp, sub_opt = skb_put(skb, sizeof(*sub_opt)); memset(sub_opt, 0x0, sizeof(*sub_opt)); - sub_tlv = skb_put(skb, sizeof(*sub_tlv)); - sub_tlv->type = BR_MRP_SUB_TLV_HEADER_TEST_AUTO_MGR; - /* 32 bit alligment shall be ensured therefore add 2 bytes */ - skb_put(skb, MRP_OPT_PADDING); + sub_tlv = skb_put_zero(skb, sizeof(*sub_tlv) + MRP_OPT_PADDING); + sub_tlv->type = BR_MRP_SUB_TLV_HEADER_TEST_AUTO_MGR; } br_mrp_skb_tlv(skb, BR_MRP_TLV_HEADER_END, 0x0); -- 2.53.0