[PATCH ipsec v4 2/9] xfrm: state: reject mark with bits outside its mask on ALLOCSPI
From: Antony Antony
Date: Tue Oct 06 2026 - 03:06:14 EST
__find_acq_core() stores the larval ACQUIRE mark raw, bypassing the
insert sanitize, so an invalid mark/mask can never match any later
masked lookup. Reject it at ALLOCSPI time instead.
Fixes: bd55775c8dd6 ("xfrm: SA lookups signature with mark")
Cc: <stable+noautosel@xxxxxxxxxx> # avoid breaking existing userspace ABI
Signed-off-by: Antony Antony <antony.antony@xxxxxxxxxxx>
---
v3->v4: added this patch
---
net/xfrm/xfrm_user.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/net/xfrm/xfrm_user.c b/net/xfrm/xfrm_user.c
index 0723d791b8b7..6b53373168b0 100644
--- a/net/xfrm/xfrm_user.c
+++ b/net/xfrm/xfrm_user.c
@@ -1916,6 +1916,9 @@ static int xfrm_alloc_userspi(struct sk_buff *skb, struct nlmsghdr *nlh,
x = NULL;
+ err = verify_mark(attrs, extack);
+ if (err)
+ goto out_noput;
mark = xfrm_mark_get(attrs, &m);
if (attrs[XFRMA_IF_ID])
--
2.47.3