[PATCH net] macvlan: cap IFLA_MACVLAN_BC_QUEUE_LEN to bound broadcast backlog

From: Xiang Mei (Microsoft)

Date: Mon Jul 06 2026 - 17:26:50 EST


The netlink policy for IFLA_MACVLAN_BC_QUEUE_LEN accepts any u32, and the
value becomes port->bc_queue_len_used, the only cap on how many skbs
macvlan_broadcast_enqueue() may queue on port->bc_queue. An unprivileged
user owning a user+net namespace (CAP_NET_ADMIN is checked only against
the target netns) can set it to 0xffffffff, so the backlog check never
trips and every broadcast frame is skb_clone()'d with GFP_ATOMIC and
queued. When RX softirq outpaces the bc_work drain (e.g. many ALLMULTI
macvlans under a broadcast flood), the queue grows unbounded and
OOMs/panics the host.

Bound the value with NLA_POLICY_MAX() at 4096, 4x the default of 1000.
This keeps headroom above the default while capping the backlog; values
above the cap are now rejected with -ERANGE at netlink parse time.

Out of memory: Killed process 141 (su) UID:0
Kernel panic - not syncing: System is deadlocked on memory
Call Trace:
vpanic (kernel/panic.c:650)
panic (kernel/panic.c:787)
out_of_memory (mm/oom_kill.c:1166)
__alloc_frozen_pages_noprof (mm/page_alloc.c:4914)
alloc_pages_mpol (mm/mempolicy.c:2490)
folio_alloc_noprof (mm/mempolicy.c:2591)
filemap_fault (mm/filemap.c:3565)

Fixes: d4bff72c8401 ("macvlan: Support for high multicast packet rate")
Reported-by: AutonomousCodeSecurity@xxxxxxxxxxxxx
Signed-off-by: Xiang Mei (Microsoft) <xmei5@xxxxxxx>
---
drivers/net/macvlan.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/net/macvlan.c b/drivers/net/macvlan.c
index c40fa331836b..d4cede6393b0 100644
--- a/drivers/net/macvlan.c
+++ b/drivers/net/macvlan.c
@@ -37,6 +37,7 @@
#define MACVLAN_HASH_BITS 8
#define MACVLAN_HASH_SIZE (1<<MACVLAN_HASH_BITS)
#define MACVLAN_DEFAULT_BC_QUEUE_LEN 1000
+#define MACVLAN_MAX_BC_QUEUE_LEN 4096

#define MACVLAN_F_PASSTHRU 1
#define MACVLAN_F_ADDRCHANGE 2
@@ -1755,7 +1756,7 @@ static const struct nla_policy macvlan_policy[IFLA_MACVLAN_MAX + 1] = {
[IFLA_MACVLAN_MACADDR] = { .type = NLA_BINARY, .len = MAX_ADDR_LEN },
[IFLA_MACVLAN_MACADDR_DATA] = { .type = NLA_NESTED },
[IFLA_MACVLAN_MACADDR_COUNT] = { .type = NLA_U32 },
- [IFLA_MACVLAN_BC_QUEUE_LEN] = { .type = NLA_U32 },
+ [IFLA_MACVLAN_BC_QUEUE_LEN] = NLA_POLICY_MAX(NLA_U32, MACVLAN_MAX_BC_QUEUE_LEN),
[IFLA_MACVLAN_BC_QUEUE_LEN_USED] = { .type = NLA_REJECT },
[IFLA_MACVLAN_BC_CUTOFF] = { .type = NLA_S32 },
};
--
2.43.0