Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1593079
| From | Jiri Slaby <jslaby@suse.cz> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | [PATCH 3.12 050/113] ipv6: fix ip6_tnl_parse_tlv_enc_lim() |
| Date | 2017-03-06 10:40 +0100 |
| Message-ID | <thXhw-6bZ-13@gated-at.bofh.it> (permalink) |
| References | <thWY9-64J-3@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
From: Eric Dumazet <edumazet@google.com>
3.12-stable review patch. If anyone has any objections, please let me know.
===============
[ Upstream commit fbfa743a9d2a0ffa24251764f10afc13eb21e739 ]
This function suffers from multiple issues.
First one is that pskb_may_pull() may reallocate skb->head,
so the 'raw' pointer needs either to be reloaded or not used at all.
Second issue is that NEXTHDR_DEST handling does not validate
that the options are present in skb->data, so we might read
garbage or access non existent memory.
With help from Willem de Bruijn.
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reported-by: Dmitry Vyukov <dvyukov@google.com>
Cc: Willem de Bruijn <willemb@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
net/ipv6/ip6_tunnel.c | 34 ++++++++++++++++++++++------------
1 file changed, 22 insertions(+), 12 deletions(-)
diff --git a/net/ipv6/ip6_tunnel.c b/net/ipv6/ip6_tunnel.c
index 9a625b1ae10f..81e40d264236 100644
--- a/net/ipv6/ip6_tunnel.c
+++ b/net/ipv6/ip6_tunnel.c
@@ -396,18 +396,19 @@ ip6_tnl_dev_uninit(struct net_device *dev)
__u16 ip6_tnl_parse_tlv_enc_lim(struct sk_buff *skb, __u8 *raw)
{
- const struct ipv6hdr *ipv6h = (const struct ipv6hdr *) raw;
- __u8 nexthdr = ipv6h->nexthdr;
- __u16 off = sizeof (*ipv6h);
+ const struct ipv6hdr *ipv6h = (const struct ipv6hdr *)raw;
+ unsigned int nhoff = raw - skb->data;
+ unsigned int off = nhoff + sizeof(*ipv6h);
+ u8 next, nexthdr = ipv6h->nexthdr;
while (ipv6_ext_hdr(nexthdr) && nexthdr != NEXTHDR_NONE) {
- __u16 optlen = 0;
struct ipv6_opt_hdr *hdr;
- if (raw + off + sizeof (*hdr) > skb->data &&
- !pskb_may_pull(skb, raw - skb->data + off + sizeof (*hdr)))
+ u16 optlen;
+
+ if (!pskb_may_pull(skb, off + sizeof(*hdr)))
break;
- hdr = (struct ipv6_opt_hdr *) (raw + off);
+ hdr = (struct ipv6_opt_hdr *)(skb->data + off);
if (nexthdr == NEXTHDR_FRAGMENT) {
struct frag_hdr *frag_hdr = (struct frag_hdr *) hdr;
if (frag_hdr->frag_off)
@@ -418,20 +419,29 @@ __u16 ip6_tnl_parse_tlv_enc_lim(struct sk_buff *skb, __u8 *raw)
} else {
optlen = ipv6_optlen(hdr);
}
+ /* cache hdr->nexthdr, since pskb_may_pull() might
+ * invalidate hdr
+ */
+ next = hdr->nexthdr;
if (nexthdr == NEXTHDR_DEST) {
- __u16 i = off + 2;
+ u16 i = 2;
+
+ /* Remember : hdr is no longer valid at this point. */
+ if (!pskb_may_pull(skb, off + optlen))
+ break;
+
while (1) {
struct ipv6_tlv_tnl_enc_lim *tel;
/* No more room for encapsulation limit */
- if (i + sizeof (*tel) > off + optlen)
+ if (i + sizeof(*tel) > optlen)
break;
- tel = (struct ipv6_tlv_tnl_enc_lim *) &raw[i];
+ tel = (struct ipv6_tlv_tnl_enc_lim *) skb->data + off + i;
/* return index of option if found and valid */
if (tel->type == IPV6_TLV_TNL_ENCAP_LIMIT &&
tel->length == 1)
- return i;
+ return i + off - nhoff;
/* else jump to next option */
if (tel->type)
i += tel->length + 2;
@@ -439,7 +449,7 @@ __u16 ip6_tnl_parse_tlv_enc_lim(struct sk_buff *skb, __u8 *raw)
i++;
}
}
- nexthdr = hdr->nexthdr;
+ nexthdr = next;
off += optlen;
}
return 0;
--
2.12.0
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
[PATCH 3.12 000/113] 3.12.71-stable review Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:20 +0100
[PATCH 3.12 001/113] x86/Kconfig: Simplify X86_IO_APIC dependencies Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:20 +0100
[PATCH 3.12 092/113] ocfs2: do not write error flag to user structure we cannot copy from/to Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:20 +0100
[PATCH 3.12 111/113] USB: cdc-acm: fix double usb_autopm_put_interface() in acm_port_activate() Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:20 +0100
[PATCH 3.12 089/113] af_packet: remove a stray tab in packet_set_ring() Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:20 +0100
[PATCH 3.12 103/113] ipv6: simplify detection of first operational link-local address on interface Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:20 +0100
[PATCH 3.12 102/113] net: 6lowpan: fix lowpan_header_create non-compression memcpy call Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:20 +0100
[PATCH 3.12 109/113] net: filter: x86: fix JIT address randomization Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:20 +0100
[PATCH 3.12 065/113] vfs: fix uninitialized flags in splice_to_pipe() Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:30 +0100
[PATCH 3.12 077/113] tty: serial: msm: Fix module autoload Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:30 +0100
[PATCH 3.12 063/113] l2tp: do not use udp_ioctl() Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:30 +0100
[PATCH 3.12 068/113] futex: Move futex_init() to core_initcall Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:30 +0100
[PATCH 3.12 076/113] net: socket: fix recvmmsg not returning error from sock_error Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:30 +0100
[PATCH 3.12 080/113] USB: serial: ftdi_sio: fix modem-status error handling Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:30 +0100
[PATCH 3.12 090/113] ext4: validate s_first_meta_bg at mount time Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:30 +0100
[PATCH 3.12 088/113] rtlwifi: rtl_usb: Fix for URB leaking when doing ifconfig up/down Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:30 +0100
[PATCH 3.12 096/113] drm/nv50/disp: min/max are reversed in nv50_crtc_gamma_set() Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:30 +0100
[PATCH 3.12 086/113] x86/platform/goldfish: Prevent unconditional loading Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:30 +0100
[PATCH 3.12 074/113] dccp: fix freeing skb too early for IPV6_RECVPKTINFO Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:30 +0100
[PATCH 3.12 075/113] irda: Fix lockdep annotations in hashbin_delete(). Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:30 +0100
[PATCH 3.12 082/113] USB: serial: ftdi_sio: fix line-status over-reporting Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:30 +0100
[PATCH 3.12 059/113] macvtap: read vnet_hdr_size once Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:30 +0100
[PATCH 3.12 091/113] ext4: fix fencepost in s_first_meta_bg validation Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:30 +0100
[PATCH 3.12 097/113] cpufreq: fix garbage kobjects on errors during suspend/resume Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:30 +0100
[PATCH 3.12 099/113] cpufreq: Clean up after a failing light-weight initialization Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:30 +0100
[PATCH 3.12 061/113] packet: round up linear to header len Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:30 +0100
[PATCH 3.12 081/113] USB: serial: ftdi_sio: fix extreme low-latency setting Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:30 +0100
[PATCH 3.12 070/113] rtc: interface: ignore expired timers when enqueuing new timers Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:30 +0100
[PATCH 3.12 060/113] sctp: avoid BUG_ON on sctp_wait_for_sndbuf Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:30 +0100
[PATCH 3.12 084/113] USB: serial: opticon: fix CTS retrieval at open Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:30 +0100
[PATCH 3.12 057/113] tcp: avoid infinite loop in tcp_splice_read() Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:30 +0100
[PATCH 3.12 071/113] net/llc: avoid BUG_ON() in skb_orphan() Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:30 +0100
[PATCH 3.12 079/113] USB: serial: cp210x: add new IDs for GE Bx50v3 boards Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:30 +0100
[PATCH 3.12 085/113] USB: serial: ark3116: fix register-accessor error handling Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:30 +0100
[PATCH 3.12 095/113] Staging: vt6655-6: potential NULL dereference in hostap_disable_hostapd() Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:30 +0100
[PATCH 3.12 069/113] printk: use rcuidle console tracepoint Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:30 +0100
[PATCH 3.12 062/113] ping: fix a null pointer dereference Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:30 +0100
[PATCH 3.12 064/113] scsi: move the nr_phys_segments assert into scsi_init_io Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:30 +0100
[PATCH 3.12 072/113] packet: fix races in fanout_add() Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:30 +0100
[PATCH 3.12 073/113] packet: Do not call fanout_release from atomic contexts Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:30 +0100
[PATCH 3.12 058/113] tun: read vnet_hdr_sz once Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:30 +0100
[PATCH 3.12 083/113] USB: serial: spcp8x5: fix modem-status handling Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:30 +0100
[PATCH 3.12 078/113] USB: serial: mos7840: fix another NULL-deref at open Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:30 +0100
[PATCH 3.12 087/113] goldfish: Sanitize the broken interrupt handler Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:30 +0100
[PATCH 3.12 023/113] USB: serial: option: add WeTelecom 0x6802 and 0x6803 products Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:40 +0100
[PATCH 3.12 037/113] USB: serial: option: add device ID for HP lt2523 (Novatel E371) Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:40 +0100
[PATCH 3.12 042/113] mac80211: Fix adding of mesh vendor IEs Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:40 +0100
[PATCH 3.12 050/113] ipv6: fix ip6_tnl_parse_tlv_enc_lim() Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:40 +0100
[PATCH 3.12 034/113] USB: serial: qcserial: add Dell DW5570 QDL Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:40 +0100
[PATCH 3.12 055/113] netlabel: out of bound access in cipso_v4_validate() Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:40 +0100
[PATCH 3.12 040/113] ARM: 8643/3: arm/ptrace: Preserve previous registers for short regset write Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:40 +0100
[PATCH 3.12 036/113] USB: Add quirk for WORLDE easykey.25 MIDI keyboard Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:40 +0100
[PATCH 3.12 041/113] target: Fix COMPARE_AND_WRITE ref leak for non GOOD status Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:40 +0100
[PATCH 3.12 051/113] ipv6: pointer math error in ip6_tnl_parse_tlv_enc_lim() Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:40 +0100
[PATCH 3.12 054/113] ipv4: keep skb->dst around in presence of IP options Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:40 +0100
[PATCH 3.12 043/113] scsi: zfcp: fix use-after-free by not tracing WKA port open/close on failed send Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:40 +0100
[PATCH 3.12 067/113] scsi: don't BUG_ON() empty DMA transfers Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:40 +0100
[PATCH 3.12 026/113] drm/nouveau/nv1a,nv1f/disp: fix memory clock rate retrieval Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:40 +0100
[PATCH 3.12 022/113] USB: serial: option: add WeTelecom WM-D200 Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:40 +0100
[PATCH 3.12 053/113] net: use a work queue to defer net_disable_timestamp() work Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:40 +0100
[PATCH 3.12 029/113] svcrpc: fix oops in absence of krb5 module Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:40 +0100
[PATCH 3.12 033/113] can: bcm: fix hrtimer/tasklet termination in bcm op removal Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:40 +0100
[PATCH 3.12 066/113] siano: make it work again with CONFIG_VMAP_STACK Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:40 +0100
[PATCH 3.12 039/113] selinux: fix off-by-one in setprocattr Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:40 +0100
[PATCH 3.12 056/113] ip6_gre: fix ip6gre_err() invalid reads Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:40 +0100
[PATCH 3.12 049/113] can: Fix kernel panic at security_sock_rcv_skb Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:40 +0100
[PATCH 3.12 044/113] ALSA: seq: Fix race at creating a queue Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:40 +0100
[PATCH 3.12 035/113] USB: serial: pl2303: add ATEN device ID Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:40 +0100
[PATCH 3.12 032/113] mm, fs: check for fatal signals in do_generic_file_read() Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:40 +0100
[PATCH 3.12 021/113] qmi_wwan/cdc_ether: add device ID for HP lt2523 (Novatel E371) WWAN card Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:40 +0100
[PATCH 3.12 031/113] mm/memory_hotplug.c: check start_pfn in test_pages_in_a_zone() Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:40 +0100
[PATCH 3.12 025/113] USB: serial: option: add even more ZTE device ids Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:40 +0100
[PATCH 3.12 038/113] ARC: [arcompact] brown paper bag bug in unaligned access delay slot fixup Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:40 +0100
[PATCH 3.12 052/113] tcp: fix 0 divide in __tcp_select_window() Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:40 +0100
[PATCH 3.12 007/113] ISDN: eicon: silence misleading array-bounds warning Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:50 +0100
[PATCH 3.12 012/113] nfs: Don't increment lock sequence ID after NFS4ERR_MOVED Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:50 +0100
[PATCH 3.12 011/113] parisc: Don't use BITS_PER_LONG in userspace-exported swab.h header Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:50 +0100
[PATCH 3.12 018/113] ipv6: addrconf: Avoid addrconf_disable_change() using RCU read-side lock Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:50 +0100
[PATCH 3.12 020/113] af_unix: move unix_mknod() out of bindlock Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:50 +0100
[PATCH 3.12 009/113] can: ti_hecc: add missing prepare and unprepare of the clock Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:50 +0100
[PATCH 3.12 016/113] platform/x86: intel_mid_powerbtn: Set IRQ_ONESHOT Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:50 +0100
[PATCH 3.12 008/113] can: c_can_pci: fix null-pointer-deref in c_can_start() - set device pointer Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:50 +0100
[PATCH 3.12 014/113] drm/i915: Don't leak edid in intel_crt_detect_ddc() Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:50 +0100
[PATCH 3.12 019/113] tcp: initialize max window for a new fastopen socket Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:50 +0100
[PATCH 3.12 015/113] s5k4ecgx: select CRC32 helper Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:50 +0100
[PATCH 3.12 003/113] net: possible use after free in dst_release Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:50 +0100
[PATCH 3.12 010/113] ARC: [arcompact] handle unaligned access delay slot corner case Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:50 +0100
[PATCH 3.12 013/113] SUNRPC: cleanup ida information when removing sunrpc module Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:50 +0100
[PATCH 3.12 017/113] net: fix harmonize_features() vs NETIF_F_HIGHDMA Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:50 +0100
[PATCH 3.12 002/113] crypto: caam - fix non-hmac hashes Jiri Slaby <jslaby@suse.cz> - 2017-03-06 10:50 +0100
Re: [PATCH 3.12 000/113] 3.12.71-stable review Guenter Roeck <linux@roeck-us.net> - 2017-03-06 15:50 +0100
Re: [PATCH 3.12 000/113] 3.12.71-stable review Jiri Slaby <jslaby@suse.cz> - 2017-03-09 21:00 +0100
Re: [PATCH 3.12 000/113] 3.12.71-stable review Shuah Khan <shuahkh@osg.samsung.com> - 2017-03-06 20:30 +0100
csiph-web