lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  PHC 
Open Source and information security mailing list archives
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date:   Tue, 19 May 2020 21:57:12 -0400
From:   Stephen Worley <>
Cc:,,,,,, Stephen Worley <>
Subject: [PATCH] net: nlmsg_cancel() if put fails for nhmsg

Fixes data remnant seen when we fail to reserve space for a
nexthop group during a larger dump.

If we fail the reservation, we goto nla_put_failure and
cancel the message.

Reproduce with the following iproute2 commands:
ip link add dummy1 type dummy
ip link add dummy2 type dummy
ip link add dummy3 type dummy
ip link add dummy4 type dummy
ip link add dummy5 type dummy
ip link add dummy6 type dummy
ip link add dummy7 type dummy
ip link add dummy8 type dummy
ip link add dummy9 type dummy
ip link add dummy10 type dummy
ip link add dummy11 type dummy
ip link add dummy12 type dummy
ip link add dummy13 type dummy
ip link add dummy14 type dummy
ip link add dummy15 type dummy
ip link add dummy16 type dummy
ip link add dummy17 type dummy
ip link add dummy18 type dummy
ip link add dummy19 type dummy
ip link add dummy20 type dummy
ip link add dummy21 type dummy
ip link add dummy22 type dummy
ip link add dummy23 type dummy
ip link add dummy24 type dummy
ip link add dummy25 type dummy
ip link add dummy26 type dummy
ip link add dummy27 type dummy
ip link add dummy28 type dummy
ip link add dummy29 type dummy
ip link add dummy30 type dummy
ip link add dummy31 type dummy
ip link add dummy32 type dummy

ip link set dummy1 up
ip link set dummy2 up
ip link set dummy3 up
ip link set dummy4 up
ip link set dummy5 up
ip link set dummy6 up
ip link set dummy7 up
ip link set dummy8 up
ip link set dummy9 up
ip link set dummy10 up
ip link set dummy11 up
ip link set dummy12 up
ip link set dummy13 up
ip link set dummy14 up
ip link set dummy15 up
ip link set dummy16 up
ip link set dummy17 up
ip link set dummy18 up
ip link set dummy19 up
ip link set dummy20 up
ip link set dummy21 up
ip link set dummy22 up
ip link set dummy23 up
ip link set dummy24 up
ip link set dummy25 up
ip link set dummy26 up
ip link set dummy27 up
ip link set dummy28 up
ip link set dummy29 up
ip link set dummy30 up
ip link set dummy31 up
ip link set dummy32 up

ip link set dummy33 up
ip link set dummy34 up

ip link set vrf-red up
ip link set vrf-blue up

ip link set dummyVRFred up
ip link set dummyVRFblue up

ip ro add dev dummy1
ip ro add dev dummy2
ip ro add dev dummy3
ip ro add dev dummy4
ip ro add dev dummy5
ip ro add dev dummy6
ip ro add dev dummy7
ip ro add dev dummy8
ip ro add dev dummy9
ip ro add dev dummy10
ip ro add dev dummy11
ip ro add dev dummy12
ip ro add dev dummy13
ip ro add dev dummy14
ip ro add dev dummy15
ip ro add dev dummy16
ip ro add dev dummy17
ip ro add dev dummy18
ip ro add dev dummy19
ip ro add dev dummy20
ip ro add dev dummy21
ip ro add dev dummy22
ip ro add dev dummy23
ip ro add dev dummy24
ip ro add dev dummy25
ip ro add dev dummy26
ip ro add dev dummy27
ip ro add dev dummy28
ip ro add dev dummy29
ip ro add dev dummy30
ip ro add dev dummy31
ip ro add dev dummy32

ip next add id 1 via dev dummy1
ip next add id 2 via dev dummy2
ip next add id 3 via dev dummy3
ip next add id 4 via dev dummy4
ip next add id 5 via dev dummy5
ip next add id 6 via dev dummy6
ip next add id 7 via dev dummy7
ip next add id 8 via dev dummy8
ip next add id 9 via dev dummy9
ip next add id 10 via dev dummy10
ip next add id 11 via dev dummy11
ip next add id 12 via dev dummy12
ip next add id 13 via dev dummy13
ip next add id 14 via dev dummy14
ip next add id 15 via dev dummy15
ip next add id 16 via dev dummy16
ip next add id 17 via dev dummy17
ip next add id 18 via dev dummy18
ip next add id 19 via dev dummy19
ip next add id 20 via dev dummy20
ip next add id 21 via dev dummy21
ip next add id 22 via dev dummy22
ip next add id 23 via dev dummy23
ip next add id 24 via dev dummy24
ip next add id 25 via dev dummy25
ip next add id 26 via dev dummy26
ip next add id 27 via dev dummy27
ip next add id 28 via dev dummy28
ip next add id 29 via dev dummy29
ip next add id 30 via dev dummy30
ip next add id 31 via dev dummy31
ip next add id 32 via dev dummy32


while [ $i -le 200 ]
ip next add id $i group 1/2/3/4/5/6/7/8/9/10/11/12/13/14/15/16/17/18/19

	echo $i



ip next add id 999 group 1/2/3/4/5/6

ip next ls


Fixes: ab84be7e54fc ("net: Initial nexthop code")
Signed-off-by: Stephen Worley <>
 net/ipv4/nexthop.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/net/ipv4/nexthop.c b/net/ipv4/nexthop.c
index 2a31c4af845e..715e14475220 100644
--- a/net/ipv4/nexthop.c
+++ b/net/ipv4/nexthop.c
@@ -276,6 +276,7 @@ static int nh_fill_node(struct sk_buff *skb, struct nexthop *nh,
 	return 0;
+	nlmsg_cancel(skb, nlh);
 	return -EMSGSIZE;

base-commit: 20a785aa52c82246055a089e55df9dac47d67da1

Powered by blists - more mailing lists