From patchwork Mon Jul 27 20:07:01 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Antonio Quartulli X-Patchwork-Id: 5134 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:190f:b0:87d:a69c:34be with SMTP id g15csp1598667maz; Mon, 27 Jul 2026 13:07:31 -0700 (PDT) X-Forwarded-Encrypted: i=2; AHgh+RqHjM3ZOyJa+6j/3gYcpEq+QfMICk8uTSANUB2SPLrF01QV44KD2q1a+vWNuvXkn0p89CuJH0IvOdk=@openvpn.net X-Received: by 2002:a05:6809:245:20b0:49e:d43f:1b94 with SMTP id 5614622812f47-4ad57fa31bcmr145952b6e.0.1785182851015; Mon, 27 Jul 2026 13:07:31 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1785182851; cv=none; d=google.com; s=arc-20260327; b=q/gXsZwgE+9yMY87IkLzxI3ttqlgEd6zZyMweB0CiCS9H0JCKL4ug8EnM9GVty9McO qR2tnJF0A35c09npqzzFfo04/fv71nkwftM1DGmvPnsWHRP84KKLNo/VdQ1QHBos1hlC AxVEDVvIOsBscmk/gQjwNUddomNHr9s4c8d8n4K69qtl+7krXE3U38F0m8uwbo5mYYpt rT4dl/MmYTQx9XQL33ye1rgs9TWNvp6pyBxUA/U8B+flDbGuJSsH1LVmA3IMofuM14Qg XKePlrWwdrAIQBh3RhwM8s/cKdBXyBLfT7QKQLCORwTmU7bB2rru950ZCCvRAtKy08JC ejmg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:cc:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature:dkim-signature; bh=xv0zSlUOk2szzstBzlGxyib7OVgXa2IUsOBKeaufRp4=; fh=BsMg/B0Yb/hS/rzP5Npz4luh0IleZm8REk1XWiWRt2A=; b=jf3x2FW0vMcpcrmWboQsl2FLM5nX7rQR9to+p0LscdIS5FTbiurH/7Q/0rLO+EHiQx sWyhVbOgSOqGU3pYmiMm7AO0YIVwTqGdM5n4x2kCPFlg9SblJUZVjlMxEftTPilOxo4a geTlbVG0RbpiQ4Tt1hUBftj1JbECnYEQYvPQYEH8bWlbAyxnyaVXsbXP89bHQQyytp6B ywqXX1EltJgz/3yVYiabp8DeSZf/P1Sp0j3XsdPXQITMLIV6UcLFLN7zvGs/nmNzYpUH l+8zNWd5vp3YtP8+/LreyIBcu7R3GwcXyFz4UGRTsCcqFGL1XjB03O7j9QLnwU6CehVE 6kSg==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=JeVWMwFn; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=YMGPaFDO; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=PPbNpmXv; dkim=neutral (body hash did not verify) header.i=@unstable.cc header.s=MBO0001 header.b=FkNWVE0I; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 5614622812f47-4ab4b3faac3si9225718b6e.66.2026.07.27.13.07.30 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Mon, 27 Jul 2026 13:07:31 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=JeVWMwFn; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=YMGPaFDO; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=PPbNpmXv; dkim=neutral (body hash did not verify) header.i=@unstable.cc header.s=MBO0001 header.b=FkNWVE0I; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type:Cc: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender :Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=xv0zSlUOk2szzstBzlGxyib7OVgXa2IUsOBKeaufRp4=; b=JeVWMwFnZr+cOsM2FArJw6mzrh EjtE5/YbiSTbtr3mjDSsEb7k1cWHBm7TyGmZY/DiQBMu1vMkgTnkuJIQwkLX/gl21RaLAfKF4ejZS swXyPRnNP+XuhYoFyBgTIalL43X4dqWx2138U23bzK6+XLTsTLr5vHrJfYPSROMm3wfk=; Received: from [127.0.0.1] (helo=sfs-ml-1.v29.lw.sourceforge.com) by sfs-ml-1.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1woRbm-0008Lt-8n; Mon, 27 Jul 2026 20:07:27 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-1.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1woRbi-0008Le-OU for openvpn-devel@lists.sourceforge.net; Mon, 27 Jul 2026 20:07:24 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=SxS5EazCkfznQezlhD63nt8VnLSO3xzQC/LLduZkApU=; b=YMGPaFDO7Ui7+2ukT8PzwuRBeL qhclj7VPKWqAqyjmL3aCJ9C98qLSikJdcmWNQL5C6vDTuaTvjULen8tTzVmh4NQ6cQLjUGRtSneD6 ivgrWTPMIBgbpk2GuLICj2REszNtBDVlXk8UPSFyULsdPIXsOLw3EaPj7KdNZpZ4XKao=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=SxS5EazCkfznQezlhD63nt8VnLSO3xzQC/LLduZkApU=; b=PPbNpmXvlU32N6e7oLL2IIEuNK 8DRoKzI4D4BCGGkmExkXq4RNCD6UQf1NSVAjG15EQ5b0EdzZkx3tncQBVyak/rwZYFGwha6qKuBc+ qEbo7UsIIrUtU73jZ5C+3wtsg/eLrJk1HQwjgmvucDSngH+JIDFd8TQUuMsByGyL+ePM=; Received: from mout-p-102.mailbox.org ([80.241.56.152]) by sfi-mx-2.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1woRbf-0001PK-NQ for openvpn-devel@lists.sourceforge.net; Mon, 27 Jul 2026 20:07:24 +0000 Received: from smtp102.mailbox.org (smtp102.mailbox.org [IPv6:2001:67c:2050:b231:465::102]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mout-p-102.mailbox.org (Postfix) with ESMTPS id 4h88l80kYVzKw2d; Mon, 27 Jul 2026 22:07:16 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=unstable.cc; s=MBO0001; t=1785182836; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=SxS5EazCkfznQezlhD63nt8VnLSO3xzQC/LLduZkApU=; b=FkNWVE0IJj9XDGynifc4JhZ9PwHEP3acyA6dxnigryZ/8zzFH5pUqvtUuYYc9Td6st9K32 tFYSUM7LNQ6tb3kQG/kJgge7BwyLUEv5pZ6bHbxuf2AOSgzTIGzmTRAQTYvTiVAXv6T8Lg 6KLMuI2qN2A1+HKIsiHXu45fA9aP9fwEaDE25nnGN6+3upNfzZ//L5avNSEv2QieueNAi6 qtc8v5V27wYHUw0AOgUiyTN5KOg0eYtjX7tM0tMg91yCbyt/+SWAR2SWuht03mudHdWQpo MoNGaWlqgrnKZPK8gCmgAp/UJnLelCnzHerbZkn36Aw9WtMEp0zwVwLhvQyPsQ== Authentication-Results: outgoing_mbo_mout; dkim=none; spf=pass (outgoing_mbo_mout: domain of a@unstable.cc designates 2001:67c:2050:b231:465::102 as permitted sender) smtp.mailfrom=a@unstable.cc From: Antonio Quartulli To: openvpn-devel@lists.sourceforge.net Date: Mon, 27 Jul 2026 22:07:01 +0200 Message-ID: <20260727200705.869169-6-a@unstable.cc> In-Reply-To: <20260727200705.869169-1-a@unstable.cc> References: <20260727200705.869169-1-a@unstable.cc> MIME-Version: 1.0 X-Rspamd-Queue-Id: 4h88l80kYVzKw2d X-Spam-Score: -0.2 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-2.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: From: Antonio Quartulli ovpn_peer_endpoints_update() builds the new remote endpoint in an on-stack struct sockaddr_storage that is left uninitialized. For IPv4 only sin_family/sin_addr/sin_port are written, leaving the 8-byt [...] Content analysis details: (-0.2 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.0 RCVD_IN_MSPIKE_H5 RBL: Excellent reputation (+5) [80.241.56.152 listed in wl.mailspike.net] -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature -0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from envelope-from domain 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain 0.0 RCVD_IN_MSPIKE_WL Mailspike good senders X-Headers-End: 1woRbf-0001PK-NQ Subject: [Openvpn-devel] [PATCH ovpn net v3 5/9] ovpn: zero-initialize sockaddr before learning a floated endpoint X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Antonio Quartulli Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1871899892959295152 X-GMAIL-MSGID: 1871899892959295152 From: Antonio Quartulli ovpn_peer_endpoints_update() builds the new remote endpoint in an on-stack struct sockaddr_storage that is left uninitialized. For IPv4 only sin_family/sin_addr/sin_port are written, leaving the 8-byte sin_zero padding as stack garbage (for IPv6, sin6_flowinfo is left uninitialized likewise). ovpn_peer_reset_sockaddr() -> ovpn_bind_from_sockaddr() then memcpy()s sizeof(struct sockaddr_in)/sizeof(struct sockaddr_in6) bytes - padding included - into bind->remote. That buffer is later hashed with jhash() over the same length to place the peer in the by_transp_addr table, so the garbage padding lands the floated peer in an essentially random bucket. Lockless lookups in ovpn_peer_get_by_transp_addr() build their key from a zero-initialized sockaddr_storage, compute a different bucket and fail to find the peer. This is also a plain use of uninitialized stack memory in jhash(). Zero-initialize the sockaddr_storage, matching what the lookup and netlink paths already do. Fixes: f0281c1d3732 ("ovpn: add support for updating local or remote UDP endpoint") Signed-off-by: Antonio Quartulli --- drivers/net/ovpn/peer.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/net/ovpn/peer.c b/drivers/net/ovpn/peer.c index 3554da01e406..be772d14ae41 100644 --- a/drivers/net/ovpn/peer.c +++ b/drivers/net/ovpn/peer.c @@ -221,7 +221,7 @@ static void __ovpn_peer_hash_transp_addr(struct ovpn_peer *peer, */ void ovpn_peer_endpoints_update(struct ovpn_peer *peer, struct sk_buff *skb) { - struct sockaddr_storage ss; + struct sockaddr_storage ss = {}; struct sockaddr_in6 *sa6; bool reset_cache = false; struct sockaddr_in *sa;