lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  PHC 
Open Source and information security mailing list archives
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date:   Fri, 24 Jan 2020 16:53:27 -0500
From:   Stephen Worley <>
        Stephen Worley <>
Subject: [PATCH] net: include struct nhmsg size in nh nlmsg size

Include the size of struct nhmsg size when calculating
how much of a payload to allocate in a new netlink nexthop
notification message.

Without this, we will fail to fill the skbuff at certain nexthop
group sizes.

You can reproduce the failure with the following iproute2 commands:

ip link add dummy1 type dummy
ip link add dummy2 type dummy
ip link add dummy3 type dummy
ip link add dummy4 type dummy
ip link add dummy5 type dummy
ip link add dummy6 type dummy
ip link add dummy7 type dummy
ip link add dummy8 type dummy
ip link add dummy9 type dummy
ip link add dummy10 type dummy
ip link add dummy11 type dummy
ip link add dummy12 type dummy
ip link add dummy13 type dummy
ip link add dummy14 type dummy
ip link add dummy15 type dummy
ip link add dummy16 type dummy
ip link add dummy17 type dummy
ip link add dummy18 type dummy
ip link add dummy19 type dummy

ip ro add dev dummy1
ip ro add dev dummy2
ip ro add dev dummy3
ip ro add dev dummy4
ip ro add dev dummy5
ip ro add dev dummy6
ip ro add dev dummy7
ip ro add dev dummy8
ip ro add dev dummy9
ip ro add dev dummy10
ip ro add dev dummy11
ip ro add dev dummy12
ip ro add dev dummy13
ip ro add dev dummy14
ip ro add dev dummy15
ip ro add dev dummy16
ip ro add dev dummy17
ip ro add dev dummy18
ip ro add dev dummy19

ip next add id 1 via dev dummy1
ip next add id 2 via dev dummy2
ip next add id 3 via dev dummy3
ip next add id 4 via dev dummy4
ip next add id 5 via dev dummy5
ip next add id 6 via dev dummy6
ip next add id 7 via dev dummy7
ip next add id 8 via dev dummy8
ip next add id 9 via dev dummy9
ip next add id 10 via dev dummy10
ip next add id 11 via dev dummy11
ip next add id 12 via dev dummy12
ip next add id 13 via dev dummy13
ip next add id 14 via dev dummy14
ip next add id 15 via dev dummy15
ip next add id 16 via dev dummy16
ip next add id 17 via dev dummy17
ip next add id 18 via dev dummy18
ip next add id 19 via dev dummy19

ip next add id 1111 group 1/2/3/4/5/6/7/8/9/10/11/12/13/14/15/16/17/18/19
ip next del id 1111

Fixes: 430a049190de ("nexthop: Add support for nexthop groups")
Signed-off-by: Stephen Worley <>
 net/ipv4/nexthop.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/net/ipv4/nexthop.c b/net/ipv4/nexthop.c
index 511eaa94e2d1..d072c326dd64 100644
--- a/net/ipv4/nexthop.c
+++ b/net/ipv4/nexthop.c
@@ -321,7 +321,9 @@ static size_t nh_nlmsg_size_single(struct nexthop *nh)
 static size_t nh_nlmsg_size(struct nexthop *nh)
-	size_t sz = nla_total_size(4);    /* NHA_ID */
+	size_t sz = NLMSG_ALIGN(sizeof(struct nhmsg));
+	sz += nla_total_size(4); /* NHA_ID */
 	if (nh->is_group)
 		sz += nh_nlmsg_size_grp(nh);

base-commit: 623c8d5c74c69a41573da5a38bb59e8652113f56

Powered by blists - more mailing lists