Thread (9 messages) 9 messages, 4 authors, 2026-06-21

Re: [PATCH net] net: dst_metadata: fix false-positive memcpy overflow in tun_dst_unclone

From: Ilya Maximets <i.maximets@ovn.org>
Date: 2026-06-19 22:59:40
Also in: linux-hardening, lkml, llvm

On 6/18/26 1:43 PM, Johan Thomsen wrote:
quoted
Johan, if you can test this one in your setup as well, that would
be great.  Thanks.

 include/net/dst_metadata.h | 7 +++++--
 1 file changed, 5 insertions(+), 2 deletions(-)
diff --git a/include/net/dst_metadata.h b/include/net/dst_metadata.h
index 1fc2fb03ce3f..f45d1e3163f0 100644
--- a/include/net/dst_metadata.h
+++ b/include/net/dst_metadata.h
@@ -164,8 +164,11 @@ static inline struct metadata_dst *tun_dst_unclone(struct sk_buff *skb)
        if (!new_md)
                return ERR_PTR(-ENOMEM);

-       memcpy(&new_md->u.tun_info, &md_dst->u.tun_info,
-              sizeof(struct ip_tunnel_info) + md_size);
+       /* Copy in two stages to keep the __counted_by happy. */
+       new_md->u.tun_info = md_dst->u.tun_info;
+       memcpy(ip_tunnel_info_opts(&new_md->u.tun_info),
+              ip_tunnel_info_opts(&md_dst->u.tun_info), md_size);
+
 #ifdef CONFIG_DST_CACHE
        /* Unclone the dst cache if there is one */
        if (new_md->u.tun_info.dst_cache.cache) {
Hi Ilya,

Sure. Just stressed it for 24 hours and - I cannot trigger the bug
with this patch applied.
Thanks, Johan!

Best regards, Ilya Maximets.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help