mirror of
				git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
				synced 2025-10-31 08:44:41 +00:00 
			
		
		
		
	cn: verify msg->len before making callback
The struct cn_msg len field comes from userspace and needs to be validated. More logical to do so here where the cn_msg pointer is pulled out of the sk_buff than the callback which is passed cn_msg * and might assume no validation is needed. Reported-by: Dan Carpenter <dan.carpenter@oracle.com> Acked-by: Evgeniy Polyakov <zbr@ioremap.net> Signed-off-by: David Fries <David@Fries.net> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
This commit is contained in:
		
							parent
							
								
									55c4e6405d
								
							
						
					
					
						commit
						a30cfa475d
					
				
					 1 changed files with 6 additions and 0 deletions
				
			
		|  | @ -141,12 +141,18 @@ EXPORT_SYMBOL_GPL(cn_netlink_send); | |||
|  */ | ||||
| static int cn_call_callback(struct sk_buff *skb) | ||||
| { | ||||
| 	struct nlmsghdr *nlh; | ||||
| 	struct cn_callback_entry *i, *cbq = NULL; | ||||
| 	struct cn_dev *dev = &cdev; | ||||
| 	struct cn_msg *msg = nlmsg_data(nlmsg_hdr(skb)); | ||||
| 	struct netlink_skb_parms *nsp = &NETLINK_CB(skb); | ||||
| 	int err = -ENODEV; | ||||
| 
 | ||||
| 	/* verify msg->len is within skb */ | ||||
| 	nlh = nlmsg_hdr(skb); | ||||
| 	if (nlh->nlmsg_len < NLMSG_HDRLEN + sizeof(struct cn_msg) + msg->len) | ||||
| 		return -EINVAL; | ||||
| 
 | ||||
| 	spin_lock_bh(&dev->cbdev->queue_lock); | ||||
| 	list_for_each_entry(i, &dev->cbdev->queue_list, callback_entry) { | ||||
| 		if (cn_cb_equal(&i->id.id, &msg->id)) { | ||||
|  |  | |||
		Loading…
	
	Add table
		
		Reference in a new issue
	
	 David Fries
						David Fries