Thread (9 messages) read the whole thread 9 messages, 4 authors, 2026-06-21

Re: [PATCH net] net: dst_metadata: fix false-positive memcpy overflow in tun_dst_unclone

From: Johan Thomsen <hidden>
Date: 2026-06-18 11:43:27
Also in: linux-hardening, lkml, llvm

quoted hunk ↗ jump to hunk
Johan, if you can test this one in your setup as well, that would
be great.  Thanks.

 include/net/dst_metadata.h | 7 +++++--
 1 file changed, 5 insertions(+), 2 deletions(-)
diff --git a/include/net/dst_metadata.h b/include/net/dst_metadata.h
index 1fc2fb03ce3f..f45d1e3163f0 100644
--- a/include/net/dst_metadata.h
+++ b/include/net/dst_metadata.h
@@ -164,8 +164,11 @@ static inline struct metadata_dst *tun_dst_unclone(struct sk_buff *skb)
        if (!new_md)
                return ERR_PTR(-ENOMEM);

-       memcpy(&new_md->u.tun_info, &md_dst->u.tun_info,
-              sizeof(struct ip_tunnel_info) + md_size);
+       /* Copy in two stages to keep the __counted_by happy. */
+       new_md->u.tun_info = md_dst->u.tun_info;
+       memcpy(ip_tunnel_info_opts(&new_md->u.tun_info),
+              ip_tunnel_info_opts(&md_dst->u.tun_info), md_size);
+
 #ifdef CONFIG_DST_CACHE
        /* Unclone the dst cache if there is one */
        if (new_md->u.tun_info.dst_cache.cache) {
Hi Ilya,

Sure. Just stressed it for 24 hours and - I cannot trigger the bug
with this patch applied.

BR
Johan
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help