Re: [PATCH net] vxlan: vnifilter: enforce exact length of GROUP/GROUP6 attributes
From: Ido Schimmel
Date: Wed Jul 08 2026 - 03:46:37 EST
On Sat, Jul 04, 2026 at 03:22:54PM -0700, Xiang Mei wrote:
> The VXLAN VNI filter entry policy declares the GROUP/GROUP6 address
> attributes as NLA_BINARY with only a maximum length, so validate_nla()
> accepts a payload shorter than the address. The GROUP consumer reads it
> with nla_get_in_addr(), an unconditional 4-byte load, so a short
> attribute over-reads up to 3 bytes of uninitialised slab data, which are
> stored into remote_ip and echoed back via RTM_GETTUNNEL, disclosing
> kernel memory.
>
> Switch both entries to NLA_POLICY_EXACT_LEN() so the validator rejects
> any GROUP/GROUP6 that is not exactly 4 / 16 bytes; a valid address is
> always sent at full width.
>
> Fixes: f9c4bb0b245c ("vxlan: vni filtering support on collect metadata device")
> Reported-by: Weiming Shi <bestswngs@xxxxxxxxx>
> Assisted-by: Claude:claude-opus-4-8
> Signed-off-by: Xiang Mei <xmei5@xxxxxxx>
Reviewed-by: Ido Schimmel <idosch@xxxxxxxxxx>