[PATCH net 0/2] net: mcast: do not write past optlen in the source filter getsockopt

From: Breno Leitao

Date: Thu Aug 06 2026 - 05:42:52 EST


getsockopt() on the multicast source filter options writes past the
buffer the caller declared. Only the fixed header is checked against
optlen. The number of sources copied out comes from gf_numsrc/
imsf_numsrc, read back from optval, and nothing bounds that count by
the space left in the buffer.

I hit this while converting the mcast getsockopt paths to sockopt_t.
Fixing it against 'net' first, so the fix is settled on its own before
the conversion goes on top.

Signed-off-by: Breno Leitao <leitao@xxxxxxxxxx>
---
Breno Leitao (2):
ipv4: mcast: getsockopt: do not overwrite past optlen
ipv6: mcast: do not write past optlen in the source filter getsockopt

net/ipv4/ip_sockglue.c | 16 ++++++++++++++++
net/ipv6/ipv6_sockglue.c | 11 +++++++++++
2 files changed, 27 insertions(+)
---
base-commit: b0057c68df711bf6a62033c072ac61c4f9d3cbc1
change-id: 20260806-mcast_fix-4db13688cbb6

Best regards,
--
Breno Leitao <leitao@xxxxxxxxxx>