[PATCH] xfrm: zero-initialise km_event in replay-notify to stop stack disclosure
From: Shubham Antil
Date: Wed Sep 30 2026 - 05:43:44 EST
xfrm_replay_notify(), xfrm_replay_notify_bmp() and
xfrm_replay_notify_esn() declare a struct km_event on the stack and
initialise only its .event and .data.aevent fields, leaving .seq and
.portid uninitialised. build_aevent() copies those two fields into the
XFRM_MSG_NEWAE netlink message header via
nlmsg_put(skb, c->portid, c->seq, ...), and the message is multicast to
the XFRMNLGRP_AEVENTS group, so two dwords of uninitialised kernel stack
are sent to group listeners on each replay event.
The request-driven paths set these header fields from the requester
(xfrm_get_ae() / xfrm_new_ae()); only the kernel-originated replay path
leaves them uninitialised. Zero-initialise the event so the header
fields are sent as 0, the correct value for a kernel-originated
notification.
Reported-by: Giovanni Vignone <gio@octane.security>
Assisted-by: LLM
Signed-off-by: Shubham Antil <shubham@octane.security>
---
net/xfrm/xfrm_replay.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/net/xfrm/xfrm_replay.c b/net/xfrm/xfrm_replay.c
index dbdf8a39df..9394953247 100644
--- a/net/xfrm/xfrm_replay.c
+++ b/net/xfrm/xfrm_replay.c
@@ -40,7 +40,7 @@ static void xfrm_replay_notify_esn(struct xfrm_state *x, int event);
void xfrm_replay_notify(struct xfrm_state *x, int event)
{
- struct km_event c;
+ struct km_event c = {};
/* we send notify messages in case
* 1. we updated on of the sequence numbers, and the seqno difference
* is at least x->replay_maxdiff, in this case we also update the
@@ -304,7 +304,7 @@ static void xfrm_replay_advance_bmp(struct xfrm_state *x, __be32 net_seq)
static void xfrm_replay_notify_bmp(struct xfrm_state *x, int event)
{
- struct km_event c;
+ struct km_event c = {};
struct xfrm_replay_state_esn *replay_esn = x->replay_esn;
struct xfrm_replay_state_esn *preplay_esn = x->preplay_esn;
@@ -356,7 +356,7 @@ static void xfrm_replay_notify_bmp(struct xfrm_state *x, int event)
static void xfrm_replay_notify_esn(struct xfrm_state *x, int event)
{
u32 seq_diff, oseq_diff;
- struct km_event c;
+ struct km_event c = {};
struct xfrm_replay_state_esn *replay_esn = x->replay_esn;
struct xfrm_replay_state_esn *preplay_esn = x->preplay_esn;
--
2.43.0