Commit 88906f55 authored by Eelco Chaudron's avatar Eelco Chaudron Committed by Jakub Kicinski
Browse files

openvswitch: Stricter validation for the userspace action



This change enhances the robustness of validate_userspace() by ensuring
that all Netlink attributes are fully contained within the parent
attribute. The previous use of nla_parse_nested_deprecated() could
silently skip trailing or malformed attributes, as it stops parsing at
the first invalid entry.

By switching to nla_parse_deprecated_strict(), we make sure only fully
validated attributes are copied for later use.

Signed-off-by: default avatarEelco Chaudron <echaudro@redhat.com>
Reviewed-by: default avatarSimon Horman <horms@kernel.org>
Acked-by: default avatarIlya Maximets <i.maximets@ovn.org>
Link: https://patch.msgid.link/67eb414e2d250e8408bb8afeb982deca2ff2b10b.1747037304.git.echaudro@redhat.com


Signed-off-by: default avatarJakub Kicinski <kuba@kernel.org>
parent 73d95284
Loading
Loading
Loading
Loading
+2 −1
Original line number Diff line number Diff line
@@ -3049,7 +3049,8 @@ static int validate_userspace(const struct nlattr *attr)
	struct nlattr *a[OVS_USERSPACE_ATTR_MAX + 1];
	int error;

	error = nla_parse_nested_deprecated(a, OVS_USERSPACE_ATTR_MAX, attr,
	error = nla_parse_deprecated_strict(a, OVS_USERSPACE_ATTR_MAX,
					    nla_data(attr), nla_len(attr),
					    userspace_policy, NULL);
	if (error)
		return error;