]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
nexthop: initialize extack in nh_res_bucket_migrate()
authorXiang Mei (Microsoft) <xmei5@asu.edu>
Mon, 13 Jul 2026 22:15:51 +0000 (22:15 +0000)
committerJakub Kicinski <kuba@kernel.org>
Tue, 21 Jul 2026 22:09:41 +0000 (15:09 -0700)
nh_res_bucket_migrate() passes an uninitialized netlink_ext_ack to
call_nexthop_res_bucket_notifiers(). When
nh_notifier_res_bucket_info_init() fails (e.g. the kzalloc returns
-ENOMEM), the error is propagated back before any notifier sets
extack._msg, and the error path formats the stale pointer with
pr_err_ratelimited("%s\n", extack._msg). With CONFIG_INIT_STACK_NONE
this dereferences uninitialized stack memory:

  Oops: general protection fault, probably for non-canonical address ...
  KASAN: maybe wild-memory-access in range [...]
  RIP: 0010:string (lib/vsprintf.c:730)
   vsnprintf (lib/vsprintf.c:2945)
   _printk (kernel/printk/printk.c:2504)
   nh_res_bucket_migrate (net/ipv4/nexthop.c:1816)
   nh_res_table_upkeep (net/ipv4/nexthop.c:1866)
   rtm_new_nexthop (net/ipv4/nexthop.c:3323)
   rtnetlink_rcv_msg (net/core/rtnetlink.c:7076)
   netlink_sendmsg (net/netlink/af_netlink.c:1900)
  Kernel panic - not syncing: Fatal exception

Zero-initialize extack so _msg is NULL on error paths that never set it.

Fixes: 7c37c7e00411 ("nexthop: Implement notifiers for resilient nexthop groups")
Reported-by: AutonomousCodeSecurity@microsoft.com
Signed-off-by: Xiang Mei (Microsoft) <xmei5@asu.edu>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Link: https://patch.msgid.link/20260713221551.3344650-1-xmei5@asu.edu
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
net/ipv4/nexthop.c

index 6205bd57aa8520f7daf58cd350e5987335becb26..44fe75004cacbb26602cb2e51318bd758ddf2183 100644 (file)
@@ -1788,8 +1788,8 @@ static bool nh_res_bucket_migrate(struct nh_res_table *res_table,
                                  bool notify_nl, bool force)
 {
        struct nh_res_bucket *bucket = &res_table->nh_buckets[bucket_index];
+       struct netlink_ext_ack extack = {};
        struct nh_grp_entry *new_nhge;
-       struct netlink_ext_ack extack;
        int err;
 
        new_nhge = list_first_entry_or_null(&res_table->uw_nh_entries,