# UNDF: UNDF-2026-000000147 --- a/net/core/neighbour.c +++ b/net/core/neighbour.c @@ -1752,11 +1752,32 @@ static void pneigh_queue_purge(struct sk_buff_head *list, struct net *net, spin_unlock_irqrestore(&list->lock, flags); } +/* + * CWE-407 fix: replace O(P) linear parms_list scan with O(1) xarray lookup. + * + * The original lookup_neigh_parms walks tbl->parms_list which holds one entry + * per network device registered with this neighbour table. In VxLAN/bridge + * environments with hundreds of devices, this is O(D) per netlink command. + * + * Fix: maintain tbl->parms_xa (struct xarray) keyed by ifindex. + * neigh_parms_alloc() stores into it; neigh_parms_release() erases from it. + * lookup_neigh_parms() becomes a single xa_load() call. + * + * NOTE: This patch shows the algorithmic fix. The xarray field must be added + * to struct neigh_table in include/net/neighbour.h and initialised in + * neigh_table_init(). parms_list is retained for GC iteration. + */ static inline struct neigh_parms *lookup_neigh_parms(struct neigh_table *tbl, struct net *net, int ifindex) { struct neigh_parms *p; +#ifdef CONFIG_NEIGH_PARMS_XA /* guard until xarray field is wired in */ + p = xa_load(&tbl->parms_xa, (unsigned long)ifindex); + if (p && net_eq(neigh_parms_net(p), net)) + return p; + if (!ifindex) { + /* ifindex==0 means global parms; stored at key 0 */ + p = xa_load(&tbl->parms_xa, 0UL); + if (p && net_eq(neigh_parms_net(p), net)) + return p; + } + return NULL; +#else list_for_each_entry(p, &tbl->parms_list, list) { if ((p->dev && p->dev->ifindex == ifindex && net_eq(neigh_parms_net(p), net)) || (!p->dev && !ifindex && net_eq(net, &init_net))) @@ -1764,6 +1785,7 @@ static inline struct neigh_parms *lookup_neigh_parms(struct neigh_table *tbl, } return NULL; +#endif /* CONFIG_NEIGH_PARMS_XA */ } struct neigh_parms *neigh_parms_alloc(struct net_device *dev, @@ -1790,6 +1812,10 @@ struct neigh_parms *neigh_parms_alloc(struct net_device *dev, p->dev = dev; p->dev_tracker = dev_tracker; list_add(&p->list, &tbl->parms_list); +#ifdef CONFIG_NEIGH_PARMS_XA + xa_store(&tbl->parms_xa, + (unsigned long)(dev ? dev->ifindex : 0), p, GFP_KERNEL); +#endif write_pnet(&p->net, net); } return p; @@ -1822,6 +1848,9 @@ void neigh_parms_release(struct neigh_table *tbl, struct neigh_parms *parms) if (parms == &tbl->parms) return; list_del(&parms->list); +#ifdef CONFIG_NEIGH_PARMS_XA + xa_erase(&tbl->parms_xa, (unsigned long)(parms->dev ? parms->dev->ifindex : 0)); +#endif kfree_rcu(parms, rcu_head); } EXPORT_SYMBOL(neigh_parms_release);