[PATCH ipsec v4 3/9] xfrm: policy: reject mark with bits outside its mask on add
From: Antony Antony
Date: Tue Oct 06 2026 - 03:07:45 EST
Same issue as states: an invalid mark/mask is silently truncated on
insert, so GETPOLICY and DELPOLICY can no longer find the policy by
id. Reject it instead.
Fixes: 0b91fda3a1f0 ("xfrm: Sanitize marks before insert")
Cc: <stable+noautosel@xxxxxxxxxx> # avoid breaking existing userspace ABI
Signed-off-by: Antony Antony <antony.antony@xxxxxxxxxxx>
---
v3->v4: added this patch
---
net/xfrm/xfrm_user.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/net/xfrm/xfrm_user.c b/net/xfrm/xfrm_user.c
index 6b53373168b0..c1571c7a2315 100644
--- a/net/xfrm/xfrm_user.c
+++ b/net/xfrm/xfrm_user.c
@@ -2307,6 +2307,9 @@ static int xfrm_add_policy(struct sk_buff *skb, struct nlmsghdr *nlh,
if (err)
return err;
err = verify_sec_ctx_len(attrs, extack);
+ if (err)
+ return err;
+ err = verify_mark(attrs, extack);
if (err)
return err;
--
2.47.3