Use AlmaLinux OS secure boot cert
Enable Btrfs support for all kernel variants
af_unix: set gc_in_progress to true in unix_gc() {CVE-2026-53361}
hpsa: bring back deprecated PCI ids #CFHack #CFHack2024
mptsas: bring back deprecated PCI ids #CFHack #CFHack2024
megaraid_sas: bring back deprecated PCI ids #CFHack #CFHack2024
qla2xxx: bring back deprecated PCI ids #CFHack #CFHack2024
qla4xxx: bring back deprecated PCI ids
be2iscsi: bring back deprecated PCI ids
kernel/rh_messages.h: enable all disabled pci devices by moving to unmaintained
gve: update QPL page registration logic to honor max_registered_pages (backport from upstream)
gve: enable reading max ring size from the device in DQO-QPL mode (backport from upstream)
53 lines
2.1 KiB
Diff
53 lines
2.1 KiB
Diff
From a9469302e0f5583c2d4a0796bf8e723f2a90e01c Mon Sep 17 00:00:00 2001
|
|
From: Florian Westphal <fwestpha@redhat.com>
|
|
Date: Wed, 13 May 2026 17:20:51 +0200
|
|
Subject: [PATCH] netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE
|
|
terminator
|
|
|
|
JIRA: https://redhat.atlassian.net/browse/RHEL-168848
|
|
Upstream Status: commit 1f3083aec883
|
|
|
|
commit 1f3083aec8836213da441270cdb1ab612dd82cf4
|
|
Author: Xiang Mei <xmei5@asu.edu>
|
|
Date: Wed Apr 1 14:20:57 2026 -0700
|
|
|
|
netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator
|
|
|
|
When batching multiple NFLOG messages (inst->qlen > 1), __nfulnl_send()
|
|
appends an NLMSG_DONE terminator with sizeof(struct nfgenmsg) payload via
|
|
nlmsg_put(), but never initializes the nfgenmsg bytes. The nlmsg_put()
|
|
helper only zeroes alignment padding after the payload, not the payload
|
|
itself, so four bytes of stale kernel heap data are leaked to userspace
|
|
in the NLMSG_DONE message body.
|
|
|
|
Use nfnl_msg_put() to build the NLMSG_DONE terminator, which initializes
|
|
the nfgenmsg payload via nfnl_fill_hdr(), consistent with how
|
|
__build_packet_message() already constructs NFULNL_MSG_PACKET headers.
|
|
|
|
Fixes: 29c5d4afba51 ("[NETFILTER]: nfnetlink_log: fix sending of multipart messages")
|
|
Reported-by: Weiming Shi <bestswngs@gmail.com>
|
|
Signed-off-by: Xiang Mei <xmei5@asu.edu>
|
|
Signed-off-by: Florian Westphal <fw@strlen.de>
|
|
|
|
Signed-off-by: Florian Westphal <fwestpha@redhat.com>
|
|
|
|
diff --git a/net/netfilter/nfnetlink_log.c b/net/netfilter/nfnetlink_log.c
|
|
index dcd2493..b1f3eda 100644
|
|
--- a/net/netfilter/nfnetlink_log.c
|
|
+++ b/net/netfilter/nfnetlink_log.c
|
|
@@ -361,10 +361,10 @@ static void
|
|
__nfulnl_send(struct nfulnl_instance *inst)
|
|
{
|
|
if (inst->qlen > 1) {
|
|
- struct nlmsghdr *nlh = nlmsg_put(inst->skb, 0, 0,
|
|
- NLMSG_DONE,
|
|
- sizeof(struct nfgenmsg),
|
|
- 0);
|
|
+ struct nlmsghdr *nlh = nfnl_msg_put(inst->skb, 0, 0,
|
|
+ NLMSG_DONE, 0,
|
|
+ AF_UNSPEC, NFNETLINK_V0,
|
|
+ htons(inst->group_num));
|
|
if (WARN_ONCE(!nlh, "bad nlskb size: %u, tailroom %d\n",
|
|
inst->skb->len, skb_tailroom(inst->skb))) {
|
|
kfree_skb(inst->skb);
|