Re: [PATCH net] vxlan: vnifilter: enforce exact length of GROUP/GROUP6 attributes
From: Jakub Kicinski
Date: Mon Jul 20 2026 - 20:25:47 EST
On Sat, 4 Jul 2026 15:22:54 -0700 Xiang Mei wrote:
> The VXLAN VNI filter entry policy declares the GROUP/GROUP6 address
> attributes as NLA_BINARY with only a maximum length, so validate_nla()
> accepts a payload shorter than the address. The GROUP consumer reads it
> with nla_get_in_addr(), an unconditional 4-byte load, so a short
> attribute over-reads up to 3 bytes of uninitialised slab data, which are
> stored into remote_ip and echoed back via RTM_GETTUNNEL, disclosing
> kernel memory.
>
> Switch both entries to NLA_POLICY_EXACT_LEN() so the validator rejects
> any GROUP/GROUP6 that is not exactly 4 / 16 bytes; a valid address is
> always sent at full width.
The netdev patch queue has overflown, if the patch is still needed
you'll have to repost, sorry.