Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1735515

[PATCH review for 4.4 40/47] netfilter: nfnl_cthelper: fix incorrect helper->expect_class_max

From "Levin, Alexander (Sasha Levin)" <alexander.levin@verizon.com>
Newsgroups linux.kernel
Subject [PATCH review for 4.4 40/47] netfilter: nfnl_cthelper: fix incorrect helper->expect_class_max
Date 2017-09-20 07:10 +0200
Message-ID <urFqP-6Vo-21@gated-at.bofh.it> (permalink)
References <urF7r-6xD-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


From: Liping Zhang <zlpnobody@gmail.com>

[ Upstream commit ae5c682113f9f94cc5e76f92cf041ee624c173ee ]

The helper->expect_class_max must be set to the total number of
expect_policy minus 1, since we will use the statement "if (class >
helper->expect_class_max)" to validate the CTA_EXPECT_CLASS attr in
ctnetlink_alloc_expect.

So for compatibility, set the helper->expect_class_max to the
NFCTH_POLICY_SET_NUM attr's value minus 1.

Also: it's invalid when the NFCTH_POLICY_SET_NUM attr's value is zero.
1. this will result "expect_policy = kzalloc(0, GFP_KERNEL);";
2. we cannot set the helper->expect_class_max to a proper value.

So if nla_get_be32(tb[NFCTH_POLICY_SET_NUM]) is zero, report -EINVAL to
the userspace.

Signed-off-by: Liping Zhang <zlpnobody@gmail.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <alexander.levin@verizon.com>
---
 net/netfilter/nfnetlink_cthelper.c | 20 +++++++++++---------
 1 file changed, 11 insertions(+), 9 deletions(-)

diff --git a/net/netfilter/nfnetlink_cthelper.c b/net/netfilter/nfnetlink_cthelper.c
index 54330fb5efaf..6d10002d23f8 100644
--- a/net/netfilter/nfnetlink_cthelper.c
+++ b/net/netfilter/nfnetlink_cthelper.c
@@ -161,6 +161,7 @@ nfnl_cthelper_parse_expect_policy(struct nf_conntrack_helper *helper,
 	int i, ret;
 	struct nf_conntrack_expect_policy *expect_policy;
 	struct nlattr *tb[NFCTH_POLICY_SET_MAX+1];
+	unsigned int class_max;
 
 	ret = nla_parse_nested(tb, NFCTH_POLICY_SET_MAX, attr,
 			       nfnl_cthelper_expect_policy_set);
@@ -170,19 +171,18 @@ nfnl_cthelper_parse_expect_policy(struct nf_conntrack_helper *helper,
 	if (!tb[NFCTH_POLICY_SET_NUM])
 		return -EINVAL;
 
-	helper->expect_class_max =
-		ntohl(nla_get_be32(tb[NFCTH_POLICY_SET_NUM]));
-
-	if (helper->expect_class_max != 0 &&
-	    helper->expect_class_max > NF_CT_MAX_EXPECT_CLASSES)
+	class_max = ntohl(nla_get_be32(tb[NFCTH_POLICY_SET_NUM]));
+	if (class_max == 0)
+		return -EINVAL;
+	if (class_max > NF_CT_MAX_EXPECT_CLASSES)
 		return -EOVERFLOW;
 
 	expect_policy = kzalloc(sizeof(struct nf_conntrack_expect_policy) *
-				helper->expect_class_max, GFP_KERNEL);
+				class_max, GFP_KERNEL);
 	if (expect_policy == NULL)
 		return -ENOMEM;
 
-	for (i=0; i<helper->expect_class_max; i++) {
+	for (i = 0; i < class_max; i++) {
 		if (!tb[NFCTH_POLICY_SET+i])
 			goto err;
 
@@ -191,6 +191,8 @@ nfnl_cthelper_parse_expect_policy(struct nf_conntrack_helper *helper,
 		if (ret < 0)
 			goto err;
 	}
+
+	helper->expect_class_max = class_max - 1;
 	helper->expect_policy = expect_policy;
 	return 0;
 err:
@@ -377,10 +379,10 @@ nfnl_cthelper_dump_policy(struct sk_buff *skb,
 		goto nla_put_failure;
 
 	if (nla_put_be32(skb, NFCTH_POLICY_SET_NUM,
-			 htonl(helper->expect_class_max)))
+			 htonl(helper->expect_class_max + 1)))
 		goto nla_put_failure;
 
-	for (i=0; i<helper->expect_class_max; i++) {
+	for (i = 0; i < helper->expect_class_max + 1; i++) {
 		nest_parms2 = nla_nest_start(skb,
 				(NFCTH_POLICY_SET+i) | NLA_F_NESTED);
 		if (nest_parms2 == NULL)
-- 
2.11.0

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH review for 4.4 01/47] drm_fourcc: Fix DRM_FORMAT_MOD_LINEAR  #define "Levin, Alexander (Sasha Levin)" <alexander.levin@verizon.com> - 2017-09-20 07:10 +0200
  [PATCH review for 4.4 19/47] IB/ipoib: rtnl_unlock can not come after  free_netdev "Levin, Alexander (Sasha Levin)" <alexander.levin@verizon.com> - 2017-09-20 07:10 +0200
  [PATCH review for 4.4 35/47] mmc: sdio: fix alignment issue in struct  sdio_func "Levin, Alexander (Sasha Levin)" <alexander.levin@verizon.com> - 2017-09-20 07:10 +0200
  [PATCH review for 4.4 37/47] netfilter: invoke synchronize_rcu after  set the _hook_ to NULL "Levin, Alexander (Sasha Levin)" <alexander.levin@verizon.com> - 2017-09-20 07:10 +0200
  [PATCH review for 4.4 11/47] sh_eth: use correct name for ECMR_MPDE  bit "Levin, Alexander (Sasha Levin)" <alexander.levin@verizon.com> - 2017-09-20 07:10 +0200
  [PATCH review for 4.4 21/47] drm/amdkfd: fix improper return value on  error "Levin, Alexander (Sasha Levin)" <alexander.levin@verizon.com> - 2017-09-20 07:10 +0200
  [PATCH review for 4.4 25/47] partitions/efi: Fix integer overflow in  GPT size calculation "Levin, Alexander (Sasha Levin)" <alexander.levin@verizon.com> - 2017-09-20 07:10 +0200
  [PATCH review for 4.4 15/47] iio: adc: hx711: Add DT binding for  avia,hx711 "Levin, Alexander (Sasha Levin)" <alexander.levin@verizon.com> - 2017-09-20 07:10 +0200
  [PATCH review for 4.4 22/47] USB: serial: mos7720: fix  control-message error handling "Levin, Alexander (Sasha Levin)" <alexander.levin@verizon.com> - 2017-09-20 07:10 +0200
  [PATCH review for 4.4 14/47] iio: adc: axp288: Drop bogus  AXP288_ADC_TS_PIN_CTRL register modifications "Levin, Alexander (Sasha Levin)" <alexander.levin@verizon.com> - 2017-09-20 07:10 +0200
  [PATCH review for 4.4 08/47] MIPS: ralink: Fix incorrect assignment  on ralink_soc "Levin, Alexander (Sasha Levin)" <alexander.levin@verizon.com> - 2017-09-20 07:10 +0200
  [PATCH review for 4.4 04/47] RDS: RDMA: Fix the composite message  user notification "Levin, Alexander (Sasha Levin)" <alexander.levin@verizon.com> - 2017-09-20 07:10 +0200
  [PATCH review for 4.4 12/47] clk: wm831x: fix usleep_range with bad  range "Levin, Alexander (Sasha Levin)" <alexander.levin@verizon.com> - 2017-09-20 07:10 +0200
    Re: [PATCH review for 4.4 12/47] clk: wm831x: fix usleep_range with  bad range Charles Keepax <ckeepax@opensource.cirrus.com> - 2017-09-22 10:50 +0200
      Re: [PATCH review for 4.4 12/47] clk: wm831x: fix usleep_range with  bad range "Levin, Alexander (Sasha Levin)" <alexander.levin@verizon.com> - 2017-09-24 02:20 +0200
  [PATCH review for 4.4 02/47] drm: bridge: add DT bindings for TI  ths8135 "Levin, Alexander (Sasha Levin)" <alexander.levin@verizon.com> - 2017-09-20 07:10 +0200
  [PATCH review for 4.4 28/47] usb: chipidea: vbus event may exist  before starting gadget "Levin, Alexander (Sasha Levin)" <alexander.levin@verizon.com> - 2017-09-20 07:10 +0200
  [PATCH review for 4.4 13/47] hwmon: (gl520sm) Fix overflows and crash  seen when writing into limit attributes "Levin, Alexander (Sasha Levin)" <alexander.levin@verizon.com> - 2017-09-20 07:10 +0200
  [PATCH review for 4.4 40/47] netfilter: nfnl_cthelper: fix incorrect  helper->expect_class_max "Levin, Alexander (Sasha Levin)" <alexander.levin@verizon.com> - 2017-09-20 07:10 +0200
  [PATCH review for 4.4 05/47] ARM: dts: r8a7790: Use R-Car Gen 2  fallback binding for msiof nodes "Levin, Alexander (Sasha Levin)" <alexander.levin@verizon.com> - 2017-09-20 07:10 +0200
  [PATCH review for 4.4 18/47] IB/ipoib: Fix deadlock over vlan_mutex "Levin, Alexander (Sasha Levin)" <alexander.levin@verizon.com> - 2017-09-20 07:10 +0200

csiph-web