Re: [PATCH] xfrm: zero-initialise km_event in replay-notify to stop stack disclosure
From: Steffen Klassert
Date: Wed Oct 07 2026 - 02:55:11 EST
On Wed, Sep 30, 2026 at 03:01:37PM +0530, Shubham Antil wrote:
> xfrm_replay_notify(), xfrm_replay_notify_bmp() and
> xfrm_replay_notify_esn() declare a struct km_event on the stack and
> initialise only its .event and .data.aevent fields, leaving .seq and
> .portid uninitialised. build_aevent() copies those two fields into the
> XFRM_MSG_NEWAE netlink message header via
> nlmsg_put(skb, c->portid, c->seq, ...), and the message is multicast to
> the XFRMNLGRP_AEVENTS group, so two dwords of uninitialised kernel stack
> are sent to group listeners on each replay event.
>
> The request-driven paths set these header fields from the requester
> (xfrm_get_ae() / xfrm_new_ae()); only the kernel-originated replay path
> leaves them uninitialised. Zero-initialise the event so the header
> fields are sent as 0, the correct value for a kernel-originated
> notification.
>
> Reported-by: Giovanni Vignone <gio@octane.security>
> Assisted-by: LLM
> Signed-off-by: Shubham Antil <shubham@octane.security>
As this is a fix, please add a 'Fixes:' tag.
Thanks!