Re: [PATCH net] vxlan: vnifilter: enforce exact length of GROUP/GROUP6 attributes

From: Xiang Mei

Date: Wed Aug 12 2026 - 17:56:36 EST


On Mon, Jul 20, 2026 at 5:25 PM Jakub Kicinski <kuba@xxxxxxxxxx> wrote:
>
> On Sat, 4 Jul 2026 15:22:54 -0700 Xiang Mei wrote:
> > The VXLAN VNI filter entry policy declares the GROUP/GROUP6 address
> > attributes as NLA_BINARY with only a maximum length, so validate_nla()
> > accepts a payload shorter than the address. The GROUP consumer reads it
> > with nla_get_in_addr(), an unconditional 4-byte load, so a short
> > attribute over-reads up to 3 bytes of uninitialised slab data, which are
> > stored into remote_ip and echoed back via RTM_GETTUNNEL, disclosing
> > kernel memory.
> >
> > Switch both entries to NLA_POLICY_EXACT_LEN() so the validator rejects
> > any GROUP/GROUP6 that is not exactly 4 / 16 bytes; a valid address is
> > always sent at full width.
>
> The netdev patch queue has overflown, if the patch is still needed
> you'll have to repost, sorry.

Thanks for the reminder. Sorry for the delayed reply. Just tested on
the latest netdev, and the patch is still needed.
I have resent with Reviewed-by: Ido Schimmel <idosch@xxxxxxxxxx>.

The resent patch:
https://lore.kernel.org/netdev/20260812215341.763123-1-xmei5@xxxxxxx/T/#u

Xiang