[Bug 297264] Exploitable bug in PF_KEY?

From: <bugzilla-noreply_at_freebsd.org>
Date: Fri, 14 Aug 2026 14:37:02 UTC
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=297264

--- Comment #5 from commit-hook@FreeBSD.org ---
A commit in branch main references this bug:

URL:
https://cgit.FreeBSD.org/src/commit/?id=cba481a7bff2fcf31420ee8b2714660e2666452b

commit cba481a7bff2fcf31420ee8b2714660e2666452b
Author:     Konstantin Belousov <kib@FreeBSD.org>
AuthorDate: 2026-08-04 15:52:53 +0000
Commit:     Konstantin Belousov <kib@FreeBSD.org>
CommitDate: 2026-08-14 14:35:38 +0000

    PF_KEY socket: limit the length of copied socket address

    for SADB_UPDATE op SADB_X_EXT_NEW_ADDRESS_SRC/DST extensions, by
    checking the sa_len matching the address family requirements before
    doing the copy.

    Also convert KEY_SETSECASIDX() and KEY_SETSECSPIDX() to functions and
    apply the sa_len clamping there.

    See https://github.com/0xdeadbeefnetwork/pfkey-sadb-overflow

    PR:     297264
    Tested by:      Wafa Hamzah <wafah@nvidia.com> (previous version)
    Reviewed by:    markj
    Sponsored by:   The FreeBSD Foundation
    MFC after:      1 week
    Differential revision:  https://reviews.freebsd.org/D58646

 sys/netipsec/key.c | 128 +++++++++++++++++++++++++++++------------------------
 1 file changed, 69 insertions(+), 59 deletions(-)

-- 
You are receiving this mail because:
You are the assignee for the bug.