* [PATCH net-next] xfrm: xfrm_user: use strscpy() for alg_name
@ 2025-08-14 19:32 Miguel García
2025-08-17 14:48 ` Steffen Klassert
0 siblings, 1 reply; 3+ messages in thread
From: Miguel García @ 2025-08-14 19:32 UTC (permalink / raw)
To: steffen.klassert, herbert, davem
Cc: edumazet, kuba, pabeni, horms, netdev, linux-kernel, skhan,
Miguel García
Replace the strcpy() calls that copy the canonical algorithm name into
alg_name with strscpy() to avoid potential overflows and guarantee NULL
termination.
Destination is alg_name in xfrm_algo/xfrm_algo_auth/xfrm_algo_aead
(size CRYPTO_MAX_ALG_NAME).
Tested in QEMU (BusyBox/Alpine rootfs):
- Added ESP AEAD (rfc4106(gcm(aes))) and classic ESP (sha256 + cbc(aes))
- Verified canonical names via ip -d xfrm state
- Checked IPComp negative (unknown algo) and deflate path
Signed-off-by: Miguel García <miguelgarciaroman8@gmail.com>
---
net/xfrm/xfrm_user.c | 10 +++++-----
1 file changed, 5 insertions(+), 5 deletions(-)
diff --git a/net/xfrm/xfrm_user.c b/net/xfrm/xfrm_user.c
index 59f258daf830..d65def556b6b 100644
--- a/net/xfrm/xfrm_user.c
+++ b/net/xfrm/xfrm_user.c
@@ -593,7 +593,7 @@ static int attach_one_algo(struct xfrm_algo **algpp, u8 *props,
if (!p)
return -ENOMEM;
- strcpy(p->alg_name, algo->name);
+ strscpy(p->alg_name, algo->name);
*algpp = p;
return 0;
}
@@ -620,7 +620,7 @@ static int attach_crypt(struct xfrm_state *x, struct nlattr *rta,
if (!p)
return -ENOMEM;
- strcpy(p->alg_name, algo->name);
+ strscpy(p->alg_name, algo->name);
x->ealg = p;
x->geniv = algo->uinfo.encr.geniv;
return 0;
@@ -649,7 +649,7 @@ static int attach_auth(struct xfrm_algo_auth **algpp, u8 *props,
if (!p)
return -ENOMEM;
- strcpy(p->alg_name, algo->name);
+ strscpy(p->alg_name, algo->name);
p->alg_key_len = ualg->alg_key_len;
p->alg_trunc_len = algo->uinfo.auth.icv_truncbits;
memcpy(p->alg_key, ualg->alg_key, (ualg->alg_key_len + 7) / 8);
@@ -684,7 +684,7 @@ static int attach_auth_trunc(struct xfrm_algo_auth **algpp, u8 *props,
if (!p)
return -ENOMEM;
- strcpy(p->alg_name, algo->name);
+ strscpy(p->alg_name, algo->name);
if (!p->alg_trunc_len)
p->alg_trunc_len = algo->uinfo.auth.icv_truncbits;
@@ -714,7 +714,7 @@ static int attach_aead(struct xfrm_state *x, struct nlattr *rta,
if (!p)
return -ENOMEM;
- strcpy(p->alg_name, algo->name);
+ strscpy(p->alg_name, algo->name);
x->aead = p;
x->geniv = algo->uinfo.aead.geniv;
return 0;
--
2.34.1
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH net-next] xfrm: xfrm_user: use strscpy() for alg_name
2025-08-14 19:32 [PATCH net-next] xfrm: xfrm_user: use strscpy() for alg_name Miguel García
@ 2025-08-17 14:48 ` Steffen Klassert
2025-08-17 19:17 ` Miguel García Román
0 siblings, 1 reply; 3+ messages in thread
From: Steffen Klassert @ 2025-08-17 14:48 UTC (permalink / raw)
To: Miguel García
Cc: herbert, davem, edumazet, kuba, pabeni, horms, netdev,
linux-kernel, skhan
On Thu, Aug 14, 2025 at 09:32:17PM +0200, Miguel García wrote:
> Replace the strcpy() calls that copy the canonical algorithm name into
> alg_name with strscpy() to avoid potential overflows and guarantee NULL
> termination.
>
> Destination is alg_name in xfrm_algo/xfrm_algo_auth/xfrm_algo_aead
> (size CRYPTO_MAX_ALG_NAME).
>
> Tested in QEMU (BusyBox/Alpine rootfs):
> - Added ESP AEAD (rfc4106(gcm(aes))) and classic ESP (sha256 + cbc(aes))
> - Verified canonical names via ip -d xfrm state
> - Checked IPComp negative (unknown algo) and deflate path
>
> Signed-off-by: Miguel García <miguelgarciaroman8@gmail.com>
Patch applied, thanks!
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH net-next] xfrm: xfrm_user: use strscpy() for alg_name
2025-08-17 14:48 ` Steffen Klassert
@ 2025-08-17 19:17 ` Miguel García Román
0 siblings, 0 replies; 3+ messages in thread
From: Miguel García Román @ 2025-08-17 19:17 UTC (permalink / raw)
To: Steffen Klassert
Cc: herbert, davem, edumazet, kuba, pabeni, horms, netdev,
linux-kernel, skhan
El dom, 17 ago 2025 a las 16:48, Steffen Klassert
(<steffen.klassert@secunet.com>) escribió:
>
> On Thu, Aug 14, 2025 at 09:32:17PM +0200, Miguel García wrote:
> > Replace the strcpy() calls that copy the canonical algorithm name into
> > alg_name with strscpy() to avoid potential overflows and guarantee NULL
> > termination.
> >
> > Destination is alg_name in xfrm_algo/xfrm_algo_auth/xfrm_algo_aead
> > (size CRYPTO_MAX_ALG_NAME).
> >
> > Tested in QEMU (BusyBox/Alpine rootfs):
> > - Added ESP AEAD (rfc4106(gcm(aes))) and classic ESP (sha256 + cbc(aes))
> > - Verified canonical names via ip -d xfrm state
> > - Checked IPComp negative (unknown algo) and deflate path
> >
> > Signed-off-by: Miguel García <miguelgarciaroman8@gmail.com>
>
> Patch applied, thanks!
Perfect, thanks!
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2025-08-17 19:17 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2025-08-14 19:32 [PATCH net-next] xfrm: xfrm_user: use strscpy() for alg_name Miguel García
2025-08-17 14:48 ` Steffen Klassert
2025-08-17 19:17 ` Miguel García Román
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®