Hi Aldo, On Tue, Sep 15, 2026 at 11:15:47AM -0300, Aldo Ariel Panzardo wrote:
__vsock_net_mode_string() returns success without updating new_mode when the transfer length is zero. Its caller then reads the uninitialized enum and may permanently store a stack-derived value in the write-once child mode.Return before inspecting or storing new_mode when no bytes were transferred. This also prevents an empty write from locking the current mode. Fixes: eafb64f40ca4 ("vsock: add netns to vsock core") Cc: [email protected] Signed-off-by: Aldo Ariel Panzardo <[email protected]> --- net/vmw_vsock/af_vsock.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/net/vmw_vsock/af_vsock.c b/net/vmw_vsock/af_vsock.c index 622dbd0467..816d25b314 100644 --- a/net/vmw_vsock/af_vsock.c +++ b/net/vmw_vsock/af_vsock.c @@ -2883,6 +2883,8 @@ static int vsock_net_child_mode_string(const struct ctl_table *table, int write, vsock_net_child_mode(net), &new_mode); if (ret) return ret; + if (!*lenp) + return 0; if (write) { /* Prevent a "local" namespace from escalating to "global", -- 2.43.0
Code LGTM. Reviewed-by: Luigi Leonardi <[email protected]> To reproduce it, I suppose we need a kernel that does not come with `CONFIG_INIT_STACK_ALL_ZERO` set. @Stefano do you think it's worth adding a test for this case? Just out of curiosity, how did you find this bug? Thanks, Luigi

