Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1539534
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | [PATCH 4.4 13/28] net/dccp: fix use-after-free in dccp_invalid_packet |
| Date | 2016-12-09 17:40 +0100 |
| Message-ID | <sMwnf-5zi-5@gated-at.bofh.it> (permalink) |
| References | <sMw3T-5rk-5@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit 648f0c28df282636c0c8a7a19ca3ce5fc80a39c3 ]
pskb_may_pull() can reallocate skb->head, we need to reload dh pointer
in dccp_invalid_packet() or risk use after free.
Bug found by Andrey Konovalov using syzkaller.
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reported-by: Andrey Konovalov <andreyknvl@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/dccp/ipv4.c | 12 +++++++-----
1 file changed, 7 insertions(+), 5 deletions(-)
--- a/net/dccp/ipv4.c
+++ b/net/dccp/ipv4.c
@@ -698,6 +698,7 @@ int dccp_invalid_packet(struct sk_buff *
{
const struct dccp_hdr *dh;
unsigned int cscov;
+ u8 dccph_doff;
if (skb->pkt_type != PACKET_HOST)
return 1;
@@ -719,18 +720,19 @@ int dccp_invalid_packet(struct sk_buff *
/*
* If P.Data Offset is too small for packet type, drop packet and return
*/
- if (dh->dccph_doff < dccp_hdr_len(skb) / sizeof(u32)) {
- DCCP_WARN("P.Data Offset(%u) too small\n", dh->dccph_doff);
+ dccph_doff = dh->dccph_doff;
+ if (dccph_doff < dccp_hdr_len(skb) / sizeof(u32)) {
+ DCCP_WARN("P.Data Offset(%u) too small\n", dccph_doff);
return 1;
}
/*
* If P.Data Offset is too too large for packet, drop packet and return
*/
- if (!pskb_may_pull(skb, dh->dccph_doff * sizeof(u32))) {
- DCCP_WARN("P.Data Offset(%u) too large\n", dh->dccph_doff);
+ if (!pskb_may_pull(skb, dccph_doff * sizeof(u32))) {
+ DCCP_WARN("P.Data Offset(%u) too large\n", dccph_doff);
return 1;
}
-
+ dh = dccp_hdr(skb);
/*
* If P.type is not Data, Ack, or DataAck and P.X == 0 (the packet
* has short sequence numbers), drop packet and return
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
[PATCH 4.4 00/28] 4.4.38-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-12-09 17:20 +0100 [PATCH 4.4 08/28] net: dsa: bcm_sf2: Ensure we re-negotiate EEE during after link change Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-12-09 17:30 +0100 [PATCH 4.4 10/28] net/sched: pedit: make sure that offset is valid Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-12-09 17:30 +0100 [PATCH 4.4 13/28] net/dccp: fix use-after-free in dccp_invalid_packet Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-12-09 17:40 +0100 [PATCH 4.4 06/28] rtnetlink: fix FDB size computation Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-12-09 17:40 +0100 [PATCH 4.4 20/28] sparc32: Fix inverted invalid_frame_pointer checks on sigreturns Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-12-09 17:40 +0100 [PATCH 4.4 17/28] geneve: avoid use-after-free of skb->data Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-12-09 17:40 +0100 [PATCH 4.4 14/28] packet: fix race condition in packet_set_ring Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-12-09 17:40 +0100 [PATCH 4.4 21/28] sparc64: Fix find_node warning if numa node cannot be found Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-12-09 17:40 +0100 [PATCH 4.4 27/28] esp4: Fix integrity verification when ESN are used Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-12-09 17:40 +0100 [PATCH 4.4 03/28] ip6_tunnel: disable caching when the traffic class is inherited Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-12-09 17:40 +0100 Re: [PATCH 4.4 00/28] 4.4.38-stable review Shuah Khan <shuah.kh@samsung.com> - 2016-12-09 19:30 +0100 Re: [PATCH 4.4 00/28] 4.4.38-stable review Guenter Roeck <linux@roeck-us.net> - 2016-12-09 23:40 +0100
csiph-web