+1
−0
Loading
When building netlink messages, tc_chain_fill_node() never initializes the tcm_info field of struct tcmsg. Since the allocation is not zeroed, kernel heap memory is leaked to userspace through this 4-byte field. The fix simply zeroes tcm_info alongside the other fields that are already initialized. Fixes: 32a4f5ec ("net: sched: introduce chain object to uapi") Signed-off-by:Yochai Eisenrich <echelonh@gmail.com> Acked-by:
Jamal Hadi Salim <jhs@mojatatu.com> Link: https://patch.msgid.link/20260328211436.1010152-1-echelonh@gmail.com Signed-off-by:
Jakub Kicinski <kuba@kernel.org>