From nobody Fri Feb 28 23:46:33 2025 X-Original-To: dev-commits-src-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4Z4PxP5dpyz59WGk; Fri, 28 Feb 2025 23:46:33 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R10" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4Z4PxP51Kqz45NL; Fri, 28 Feb 2025 23:46:33 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1740786393; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=UqHv+VR6W1DZ29G22niNQa2uT5+SYyVMI0HNDdvTK9U=; b=nUvGINFgqEZuMeJgycrBAxXmjbABnMF/6QQ6FzaqBv3ePX+wMRRcPo8G7djHfKctLyuBnh cV7z4orRvkCLRGjOBlPShRm0vm3gPuEb9gl3wxbEUy955A+K2fdcgUTU678+p0/umtrLKM rE1fheF4HmxV2wKdmxANrXdLJdXQpgyuU+Ot2TsoIuXYBzLUUOSWVA+gqPiIpyZxtmm3e/ qBd1QM2W1r/9BLfURMcZqjY7H1dMMXCDjv8Q5e8GfHcbqeq7C3AH9XEhmDcD83wI2XfU6T C0vA5pUFGan8OQLhBiv7Js6UL9sY1b271Zvk0VQX5ctOY4mumjY6GuP1wuM9IQ== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1740786393; a=rsa-sha256; cv=none; b=CxL5rBJfMGpjG8Ol67Y80axZ6WM7s6O6HIP2kjTGIRPr3bwxYtdrBFIQf0jn9qM7XPy8ri zCZjV4SGcJtsG8ykpSqwM/3RbrctYlehQ071Eg+pPm7nTq6HAnRX/f9vKNtywnrvkDgn1J b/XdL8toe5/nUzrYua7WLWqB65tLcYht2K9SivoOE+jpnr5l7ajeDnqddKUbzcuQ8nuYfZ /nDS8kiqzv1VVjlK1GYB5nadk4BlS9CCvsxp0ws7zLxqhpIfihLPT5s+xiXgN6vlywSnxD HfTRYpJISetebRK2yOh1UkH/L7hpeOaflz0CvWwWEYteyyeZE3TGlDAPSeIG3A== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1740786393; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=UqHv+VR6W1DZ29G22niNQa2uT5+SYyVMI0HNDdvTK9U=; b=B+4VCOYBCsx6Tw/gZBD0lZDlKP+2X25AXKApV+kTjDMtHdHVsFGAEpSpFLOC7h37FH7NVN 7HGi3YQ2N+3H12QiXN8ouqvpxePCWjBCyAwdxmY+aORto7TDc98Rkm8YabQQey4uAPvYWG dO919qNw8PgoXqTxM/ysiC+ljx6oTilSbh/vLnfMA/i+JEIzh/JDKmhIUsDxugAt2Afyp2 pJrsyVgKu9VVluRMWleAHAKmcHkvJ4j3I0tXok5ilg1ElBNWKgjfAOb1GclONMna12exoV ZXR5T8Q1hRYwOvs7OoBHc0vW6EK96UbSQScOVoVdPJIITXiOmjfFyud8MDGzgQ== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4Z4PxP4JZ3zqc9; Fri, 28 Feb 2025 23:46:33 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.18.1/8.18.1) with ESMTP id 51SNkXDn079088; Fri, 28 Feb 2025 23:46:33 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.18.1/8.18.1/Submit) id 51SNkXiY079084; Fri, 28 Feb 2025 23:46:33 GMT (envelope-from git) Date: Fri, 28 Feb 2025 23:46:33 GMT Message-Id: <202502282346.51SNkXiY079084@gitrepo.freebsd.org> To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-main@FreeBSD.org From: Gleb Smirnoff Subject: git: a80bbc4e9597 - main - netlink: refuse a send(2) that is larger than socket buffer List-Id: Commit messages for all branches of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-all@freebsd.org Sender: owner-dev-commits-src-all@FreeBSD.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: glebius X-Git-Repository: src X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: a80bbc4e9597530b91735ebf366a2a62dc27a8d8 Auto-Submitted: auto-generated The branch main has been updated by glebius: URL: https://cgit.FreeBSD.org/src/commit/?id=a80bbc4e9597530b91735ebf366a2a62dc27a8d8 commit a80bbc4e9597530b91735ebf366a2a62dc27a8d8 Author: Gleb Smirnoff AuthorDate: 2025-02-28 23:39:15 +0000 Commit: Gleb Smirnoff CommitDate: 2025-02-28 23:39:15 +0000 netlink: refuse a send(2) that is larger than socket buffer The Netlink RFC doesn't say that explicitly, but general discussion seems to state that a single netlink message shall be delivered in a single send(2) to the socket. So, if a single message doesn't fit into buffer it is clear EMSGSIZE. The RFC is unclear if application is allowed to send several smaller messages with a single syscall potentially overflowing the buffer and whether kernel should accept any of them. At the moment, no legit application does that. So, decision was taken not to overload nl_sosend() with a message parsing logic and deny any oversized write. Reported-by: syzbot+eb5db60d36b005dbccf5@syzkaller.appspotmail.com --- sys/netlink/netlink_domain.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/sys/netlink/netlink_domain.c b/sys/netlink/netlink_domain.c index a7ceae687d86..74b46114716e 100644 --- a/sys/netlink/netlink_domain.c +++ b/sys/netlink/netlink_domain.c @@ -568,6 +568,9 @@ nl_sosend(struct socket *so, struct sockaddr *addr, struct uio *uio, if (__predict_false(uio->uio_resid < sizeof(struct nlmsghdr))) return (ENOBUFS); /* XXXGL: any better error? */ + if (__predict_false(uio->uio_resid > sb->sb_hiwat)) + return (EMSGSIZE); + error = SOCK_IO_SEND_LOCK(so, SBLOCKWAIT(flags)); if (error) return (error);