Commit 5e9c8baee032 for kernel

commit 5e9c8baee0329fbefe7c67aea945e2a07f15e98b
Author: Yehyeong Lee <yhlee@isslab.korea.ac.kr>
Date:   Wed Jul 22 21:28:17 2026 +0900

    net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD

    net_dm_packet_report_fill() and net_dm_hw_packet_report_fill() open code
    the NET_DM_ATTR_PAYLOAD attribute to avoid zeroing the packet payload
    before overwriting it with skb_copy_bits().

    skb_put() reserves nla_total_size(payload_len), i.e. the header plus the
    NLA_ALIGN() padding, but only payload_len bytes are copied in. When
    payload_len is not a multiple of 4 the 1-3 padding bytes are never
    initialized and are leaked to user space inside the netlink message.

    KMSAN confirms the leak for the software path when the packet payload
    length is not 4-byte aligned:

      BUG: KMSAN: kernel-infoleak in _copy_to_iter
       _copy_to_iter
       __skb_datagram_iter
       skb_copy_datagram_iter
       netlink_recvmsg
       sock_recvmsg
       __sys_recvfrom
      Uninit was created at:
       kmem_cache_alloc_node_noprof
       __alloc_skb
       net_dm_packet_work
      Bytes 173-175 of 176 are uninitialized

    Use __nla_reserve(), which sets up the attribute header and zeroes the
    padding, instead of open coding the attribute construction.

    Fixes: ca30707dee2b ("drop_monitor: Add packet alert mode")
    Fixes: 5e58109b1ea4 ("drop_monitor: Add support for packet alert mode for hardware drops")
    Suggested-by: Eric Dumazet <edumazet@google.com>
    Signed-off-by: Yehyeong Lee <yhlee@isslab.korea.ac.kr>
    Link: https://patch.msgid.link/20260722122817.5548-1-yhlee@isslab.korea.ac.kr
    Signed-off-by: Jakub Kicinski <kuba@kernel.org>

diff --git a/net/core/drop_monitor.c b/net/core/drop_monitor.c
index 2bf3cab5e557..b4d1ff2829b6 100644
--- a/net/core/drop_monitor.c
+++ b/net/core/drop_monitor.c
@@ -671,9 +671,7 @@ static int net_dm_packet_report_fill(struct sk_buff *msg, struct sk_buff *skb,
 	if (nla_put_u16(msg, NET_DM_ATTR_PROTO, be16_to_cpu(skb->protocol)))
 		goto nla_put_failure;

-	attr = skb_put(msg, nla_total_size(payload_len));
-	attr->nla_type = NET_DM_ATTR_PAYLOAD;
-	attr->nla_len = nla_attr_size(payload_len);
+	attr = __nla_reserve(msg, NET_DM_ATTR_PAYLOAD, payload_len);
 	if (skb_copy_bits(skb, 0, nla_data(attr), payload_len))
 		goto nla_put_failure;

@@ -831,9 +829,7 @@ static int net_dm_hw_packet_report_fill(struct sk_buff *msg,
 	if (nla_put_u16(msg, NET_DM_ATTR_PROTO, be16_to_cpu(skb->protocol)))
 		goto nla_put_failure;

-	attr = skb_put(msg, nla_total_size(payload_len));
-	attr->nla_type = NET_DM_ATTR_PAYLOAD;
-	attr->nla_len = nla_attr_size(payload_len);
+	attr = __nla_reserve(msg, NET_DM_ATTR_PAYLOAD, payload_len);
 	if (skb_copy_bits(skb, 0, nla_data(attr), payload_len))
 		goto nla_put_failure;