Re: [PATCH net] nexthop: initialize extack in nh_res_bucket_migrate()
From: Ido Schimmel
Date: Tue Jul 14 2026 - 06:45:11 EST
On Mon, Jul 13, 2026 at 10:15:51PM +0000, Xiang Mei (Microsoft) wrote:
> nh_res_bucket_migrate() passes an uninitialized netlink_ext_ack to
> call_nexthop_res_bucket_notifiers(). When
> nh_notifier_res_bucket_info_init() fails (e.g. the kzalloc returns
> -ENOMEM), the error is propagated back before any notifier sets
> extack._msg, and the error path formats the stale pointer with
> pr_err_ratelimited("%s\n", extack._msg). With CONFIG_INIT_STACK_NONE
> this dereferences uninitialized stack memory:
>
> Oops: general protection fault, probably for non-canonical address ...
> KASAN: maybe wild-memory-access in range [...]
> RIP: 0010:string (lib/vsprintf.c:730)
> vsnprintf (lib/vsprintf.c:2945)
> _printk (kernel/printk/printk.c:2504)
> nh_res_bucket_migrate (net/ipv4/nexthop.c:1816)
> nh_res_table_upkeep (net/ipv4/nexthop.c:1866)
> rtm_new_nexthop (net/ipv4/nexthop.c:3323)
> rtnetlink_rcv_msg (net/core/rtnetlink.c:7076)
> netlink_sendmsg (net/netlink/af_netlink.c:1900)
> Kernel panic - not syncing: Fatal exception
>
> Zero-initialize extack so _msg is NULL on error paths that never set it.
>
> Fixes: 7c37c7e00411 ("nexthop: Implement notifiers for resilient nexthop groups")
> Reported-by: AutonomousCodeSecurity@xxxxxxxxxxxxx
> Signed-off-by: Xiang Mei (Microsoft) <xmei5@xxxxxxx>
Reviewed-by: Ido Schimmel <idosch@xxxxxxxxxx>
It's very unlikely that nh_notifier_res_bucket_info_init() will fail. I
assume that fault injection was used.
remove_nh_grp_entry() also doesn't initialize extack, but
call_nexthop_notifiers() is using NL_SET_ERR_MSG(). Still, the same
problem can happen if a listener is returning an error without setting
extack. Please send a separate patch (targeted at net-next, no Fixes
tag) to make remove_nh_grp_entry() consistent with
nh_res_bucket_migrate().