Page MenuHomeFreeBSD

netlink: Fully clear parser state between messages
ClosedPublic

Authored by des on Jul 30 2025, 1:36 PM.
Tags
None
Referenced Files
Unknown Object (File)
Wed, Apr 29, 3:34 PM
Unknown Object (File)
Wed, Apr 29, 3:29 PM
Unknown Object (File)
Tue, Apr 28, 11:01 PM
Unknown Object (File)
Tue, Apr 28, 11:00 PM
Unknown Object (File)
Mon, Apr 27, 9:41 PM
Unknown Object (File)
Sun, Apr 26, 1:03 PM
Unknown Object (File)
Sun, Apr 19, 1:48 PM
Unknown Object (File)
Sun, Apr 19, 1:23 PM
Subscribers

Details

Summary

Failing to reset the cookie between messages can lead to an attempt
to interpret a zeroed buffer as a struct nlattr, causing a length
calculation to underflow, resulting in a memcpy() call where the
length exceeds the actual size of the buffer.

MFC after: 1 week
PR: 283797

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable