Skip to content

Commit 3e80233

Browse files
winminopsiff
authored andcommitted
tap: fix stack info leak in tap_ioctl() SIOCGIFHWADDR
[ Upstream commit bddc09212c24934643bd44fc794748d2bbb3b6cd ] In the SIOCGIFHWADDR path, tap_ioctl() copies 16 bytes of an uninitialised on-stack struct sockaddr_storage to userspace via ifr_hwaddr, but netif_get_mac_address() only writes sa_family and dev->addr_len (6 for Ethernet) bytes, leaving sa_data[6..13] uninitialised. Those 8 trailing bytes leak kernel stack contents; SIOCGIFHWADDR on a macvtap chardev returns kernel .text and direct-map pointers, defeating KASLR. Initialise ss at declaration. Fixes: 3b23a32 ("net: fix dev_ifsioc_locked() race condition") Reported-by: Xiang Mei <xmei5@asu.edu> Signed-off-by: Weiming Shi <bestswngs@gmail.com> Reviewed-by: Willem de Bruijn <willemb@google.com> Link: https://patch.msgid.link/20260520075736.3415676-3-bestswngs@gmail.com Signed-off-by: Jakub Kicinski <kuba@kernel.org> Signed-off-by: Sasha Levin <sashal@kernel.org> (cherry picked from commit 719007c3492f0f1f9e9cdbed8ac45ba45bb13eeb) Signed-off-by: Wentao Guan <guanwentao@uniontech.com>
1 parent dbd851d commit 3e80233

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

drivers/net/tap.c

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -919,11 +919,11 @@ static long tap_ioctl(struct file *file, unsigned int cmd,
919919
struct tap_queue *q = file->private_data;
920920
struct tap_dev *tap;
921921
void __user *argp = (void __user *)arg;
922+
struct sockaddr_storage ss = {};
922923
struct ifreq __user *ifr = argp;
923924
unsigned int __user *up = argp;
924925
unsigned short u;
925926
int __user *sp = argp;
926-
struct sockaddr_storage ss;
927927
int s;
928928
int ret;
929929

0 commit comments

Comments
 (0)