* [PATCH net] netlink: reset skb headers before unicast and multicast filtering
@ 2026-10-06 22:42 Kyle Zeng
2026-10-06 22:55 ` netdev-bot+sinfo
0 siblings, 1 reply; 4+ messages in thread
From: Kyle Zeng @ 2026-10-06 22:42 UTC (permalink / raw)
To: netdev
Cc: linux-kernel, davem, edumazet, kuba, pabeni, outbounddisclosures,
Kyle Zeng
Socket filters can use SKF_NET_OFF and SKF_LL_OFF to read relative to
an skb's network and MAC headers. Netlink producers may reserve
headroom without resetting those headers, allowing a receiving socket's
filter to read data before the initialized message.
For example, IWPM HELLO replies are allocated with dev_alloc_skb(),
which reserves NET_SKB_PAD bytes. An unprivileged NETLINK_RDMA user can
attach a classic socket filter and disclose this headroom through the
length of the delivered reply. The resets in netlink_dump() do not help
because IWPM sends a separately allocated skb through netlink_unicast().
Reset both headers before running the receiver's filter in unicast and
broadcast delivery, as is already done for dump skbs. This also covers
other netlink producers that reserve headroom without changing their
allocation or message-building code.
Fixes: b1153f29ee07 ("netlink: make socket filters work on netlink")
Assisted-by: Codex:gpt-6-astra
Signed-off-by: Kyle Zeng <kylebot@openai.com>
---
net/netlink/af_netlink.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/net/netlink/af_netlink.c b/net/netlink/af_netlink.c
index 9fdf964224ab..01af3bb144ae 100644
--- a/net/netlink/af_netlink.c
+++ b/net/netlink/af_netlink.c
@@ -1363,6 +1363,8 @@ int netlink_unicast(struct sock *ssk, struct sk_buff *skb,
if (netlink_is_kernel(sk))
return netlink_unicast_kernel(sk, skb, ssk);
+ skb_reset_network_header(skb);
+ skb_reset_mac_header(skb);
if (sk_filter(sk, skb)) {
err = skb->len;
kfree_skb(skb);
@@ -1497,6 +1499,8 @@ static void do_one_broadcast(struct sock *sk,
goto out;
}
+ skb_reset_network_header(p->skb2);
+ skb_reset_mac_header(p->skb2);
if (sk_filter(sk, p->skb2)) {
kfree_skb(p->skb2);
p->skb2 = NULL;
^ permalink raw reply [flat|nested] 4+ messages in thread* Re: [PATCH net] netlink: reset skb headers before unicast and multicast filtering
2026-10-06 22:42 [PATCH net] netlink: reset skb headers before unicast and multicast filtering Kyle Zeng
@ 2026-10-06 22:55 ` netdev-bot+sinfo
2026-10-07 5:17 ` Kyle Zeng
2026-10-07 5:19 ` Kyle Zeng
0 siblings, 2 replies; 4+ messages in thread
From: netdev-bot+sinfo @ 2026-10-06 22:55 UTC (permalink / raw)
To: Kyle Zeng
Cc: netdev, linux-kernel, davem, edumazet, kuba, pabeni, outbounddisclosures
Hi!
This is an automated message. This series looks like a fix, but its
commit messages seem to be missing some information:
- Whether the issue was actually triggered, or is only theoretical
(e.g. found by code inspection). If it was triggered please include
the symptoms, like the stack trace or error messages.
Please do not repost the series just to address the above. Instead,
reply to this email with the missing information, so that reviewers
can take it into account. If the series needs another revision for
other reasons, please include the information in the commit messages
then.
The evaluation is done by an LLM so it may be wrong, if you think
that is the case please reply and explain.
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH net] netlink: reset skb headers before unicast and multicast filtering
2026-10-06 22:55 ` netdev-bot+sinfo
@ 2026-10-07 5:17 ` Kyle Zeng
2026-10-07 5:19 ` Kyle Zeng
1 sibling, 0 replies; 4+ messages in thread
From: Kyle Zeng @ 2026-10-07 5:17 UTC (permalink / raw)
To: netdev-bot+sinfo
Cc: netdev, linux-kernel, davem, edumazet, kuba, pabeni, outbounddisclosures
On Tue, Oct 06, 2026 at 10:55:19PM +0000, netdev-bot+sinfo@kernel.org wrote:
> Hi!
>
> This is an automated message. This series looks like a fix, but its
> commit messages seem to be missing some information:
>
> - Whether the issue was actually triggered, or is only theoretical
> (e.g. found by code inspection). If it was triggered please include
> the symptoms, like the stack trace or error messages.
>
> Please do not repost the series just to address the above. Instead,
> reply to this email with the missing information, so that reviewers
> can take it into account. If the series needs another revision for
> other reasons, please include the information in the commit messages
> then.
>
> The evaluation is done by an LLM so it may be wrong, if you think
> that is the case please reply and explain.
I have PoC for this issue and the symptom is that it can lead to
information leak.
Best,
Kyle
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH net] netlink: reset skb headers before unicast and multicast filtering
2026-10-06 22:55 ` netdev-bot+sinfo
2026-10-07 5:17 ` Kyle Zeng
@ 2026-10-07 5:19 ` Kyle Zeng
1 sibling, 0 replies; 4+ messages in thread
From: Kyle Zeng @ 2026-10-07 5:19 UTC (permalink / raw)
To: netdev-bot+sinfo
Cc: netdev, linux-kernel, davem, edumazet, kuba, pabeni, outbounddisclosures
On Tue, Oct 06, 2026 at 10:55:19PM +0000, netdev-bot+sinfo@kernel.org wrote:
> Hi!
>
> This is an automated message. This series looks like a fix, but its
> commit messages seem to be missing some information:
>
> - Whether the issue was actually triggered, or is only theoretical
> (e.g. found by code inspection). If it was triggered please include
> the symptoms, like the stack trace or error messages.
>
> Please do not repost the series just to address the above. Instead,
> reply to this email with the missing information, so that reviewers
> can take it into account. If the series needs another revision for
> other reasons, please include the information in the commit messages
> then.
>
> The evaluation is done by an LLM so it may be wrong, if you think
> that is the case please reply and explain.
I have a PoC for this issue and the symptom is that it can lead to
information leak.
Best,
Kyle
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-10-07 5:19 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-06 22:42 [PATCH net] netlink: reset skb headers before unicast and multicast filtering Kyle Zeng
2026-10-06 22:55 ` netdev-bot+sinfo
2026-10-07 5:17 ` Kyle Zeng
2026-10-07 5:19 ` Kyle Zeng
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®