Page MenuHomeFreeBSD

pfsync: Avoid transmitting uninitialized bytes in pfsync_sendout()
ClosedPublic

Authored by markj on Nov 3 2023, 10:05 PM.
Tags
None
Referenced Files
Unknown Object (File)
Wed, Jun 10, 7:50 AM
Unknown Object (File)
May 24 2026, 7:50 PM
Unknown Object (File)
May 22 2026, 8:23 PM
Unknown Object (File)
May 20 2026, 10:23 PM
Unknown Object (File)
May 17 2026, 12:26 AM
Unknown Object (File)
May 11 2026, 10:33 PM
Unknown Object (File)
May 11 2026, 9:42 PM
Unknown Object (File)
Apr 22 2026, 5:49 AM

Details

Summary

When IPv6 support was added to pfsync, PFSYNC_MINPKT increased such that
we always allocate enough space for either IPv4 or IPv6 headers. IPv6
headers are 20 bytes larger than IPv4 headers. When pfsync_sendout()
does its thing, it ends up allocating enough space for either; thus when
transmitting an IPv4 packet, the last 20 bytes of the buffer are left
uninitialized.

Fix the problem by stashing the length in a local variable and adjusting
it depending on the address family in use.

While here, just zero the entire buffer in one go rather than being
careful to initialize each subheader. This seems simpler and less error
prone.

Fixes: 6fc7fc2dbb2b ("pfsync: transport over IPv6")
Reported by: KMSAN

Test Plan

pfsync regression tests

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Skipped
Unit
Tests Skipped
Build Status
Buildable 54274
Build 51164: arc lint + arc unit