Re: [PATCH net v3 14/14] rxrpc: Remove OOB challenge/response code

From: David Howells

Date: Thu Jul 23 2026 - 04:31:46 EST


Simon Horman <horms@xxxxxxxxxx> wrote:

> [Severity: Critical]
> Does removing these constants from the UAPI header violate the kernel's
> policy against breaking userspace?
>
> Any userspace program that includes linux/rxrpc.h and references the
> removed RXRPC_OOB_ID or related constants will now fail to compile.
> ...
> [Severity: Critical]
> Does this change break backwards compatibility for existing applications?

Yep. I explained my justification for that in the cover. I don't expect
anything outside of my own tools to use the API, plus this particular facet of
the API has only been around for a short time. Further, the underlying
mechanism in the kernel is replaced here, so the OOB challenge-response API is
no longer effective.

> [Severity: Critical]
> Can this sequence cause memory corruption and an out-of-bounds information
> leak via RXRPC_RESPONSE_APPDATA?
>
> Looking at the remaining sendmsg code in net/rxrpc/sendmsg.c, an inverted
> check incorrectly rejects user keys but accepts the keyring:

This is the same complaint as was raised against an earlier patch.

David