Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1589470

Re: [PATCH] net: don't call strlen() on the user buffer in packet_bind_spkt()

From Eric Dumazet <eric.dumazet@gmail.com>
Newsgroups linux.kernel
Subject Re: [PATCH] net: don't call strlen() on the user buffer in packet_bind_spkt()
Date 2017-02-28 14:50 +0100
Message-ID <tfQk9-56u-1@gated-at.bofh.it> (permalink)
References <tfPR8-4Up-23@gated-at.bofh.it> <tfQaw-51i-69@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Tue, 2017-02-28 at 05:33 -0800, Eric Dumazet wrote:

> It looks a bug in this implementation of strlcpy() then.
> 

Apparently strlcpy(dest, src, size)  returns strlen(src), so we can not
use it in this context.

> sizeof(name) is 15.
> 
> If you use strncpy(X, uaddr->sa_data, 15) , then you might access
> uaddr->sa_data[14] and this would still be wrong, since sa_data has 14
> bytes only :
> 
> 
> struct sockaddr {
>   sa_family_t sa_family;
>   char        sa_data[14];
> };


Maybe then :
diff --git a/net/packet/af_packet.c b/net/packet/af_packet.c
index 2bd0d1949312c3d71c4b33529316dcfe76fa28f1..d2e7caa79d2604363316c7316864bed1f4971d29 100644
--- a/net/packet/af_packet.c
+++ b/net/packet/af_packet.c
@@ -3103,7 +3103,7 @@ static int packet_bind_spkt(struct socket *sock, struct sockaddr *uaddr,
 			    int addr_len)
 {
 	struct sock *sk = sock->sk;
-	char name[15];
+	char name[sizeof(uaddr->sa_data) + 1];
 
 	/*
 	 *	Check legality
@@ -3111,7 +3111,8 @@ static int packet_bind_spkt(struct socket *sock, struct sockaddr *uaddr,
 
 	if (addr_len != sizeof(struct sockaddr))
 		return -EINVAL;
-	strlcpy(name, uaddr->sa_data, sizeof(name));
+	memcpy(name, uaddr->sa_data, sizeof(uaddr->sa_data));
+	name[sizeof(uaddr->sa_data)] = 0;
 
 	return packet_do_bind(sk, name, 0, pkt_sk(sk)->num);
 }

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH] net: don't call strlen() on the user buffer in packet_bind_spkt() Alexander Potapenko <glider@google.com> - 2017-02-28 14:20 +0100
  Re: [PATCH] net: don't call strlen() on the user buffer in  packet_bind_spkt() Eric Dumazet <eric.dumazet@gmail.com> - 2017-02-28 14:40 +0100
    Re: [PATCH] net: don't call strlen() on the user buffer in  packet_bind_spkt() Eric Dumazet <eric.dumazet@gmail.com> - 2017-02-28 14:50 +0100
      Re: [PATCH] net: don't call strlen() on the user buffer in packet_bind_spkt() Alexander Potapenko <glider@google.com> - 2017-02-28 14:50 +0100
        Re: [PATCH] net: don't call strlen() on the user buffer in  packet_bind_spkt() Eric Dumazet <eric.dumazet@gmail.com> - 2017-02-28 15:10 +0100
    Re: [PATCH] net: don't call strlen() on the user buffer in packet_bind_spkt() Alexander Potapenko <glider@google.com> - 2017-02-28 15:00 +0100

csiph-web