Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1601791
| From | Eric Dumazet <eric.dumazet@gmail.com> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | Re: net/udp: slab-out-of-bounds Read in udp_recvmsg |
| Date | 2017-03-15 23:50 +0100 |
| Message-ID | <tlpTX-5Og-5@gated-at.bofh.it> (permalink) |
| References | <tljlw-1aZ-27@gated-at.bofh.it> <tljES-1xz-15@gated-at.bofh.it> <tljOy-1CE-21@gated-at.bofh.it> <tlphg-5w5-15@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On Wed, 2017-03-15 at 15:08 -0700, David Miller wrote:
> From: Eric Dumazet <eric.dumazet@gmail.com>
> Date: Wed, 15 Mar 2017 09:10:33 -0700
>
> > @@ -692,12 +692,17 @@ void __sock_recv_timestamp(struct msghdr *msg, struct sock *sk,
> > ktime_to_timespec_cond(shhwtstamps->hwtstamp, tss.ts + 2))
> > empty = 0;
> > if (!empty) {
> > + unsigned int hlen = skb_headlen(skb);
> > +
> > put_cmsg(msg, SOL_SOCKET,
> > SCM_TIMESTAMPING, sizeof(tss), &tss);
> >
> > - if (skb->len && (sk->sk_tsflags & SOF_TIMESTAMPING_OPT_STATS))
> > + if (hlen &&
> > + (sk->sk_tsflags & SOF_TIMESTAMPING_OPT_STATS) &&
> > + sk->sk_protocol == IPPROTO_TCP &&
> > + sk->sk_type == SOCK_STREAM)
> > put_cmsg(msg, SOL_SOCKET, SCM_TIMESTAMPING_OPT_STATS,
> > - skb->len, skb->data);
> > + hlen, skb->data);
>
> Hmmm, what is the true intention of SOF_TIMESTAMPING_OPT_STATS then? The
> existing code seems to want to dump the entire SKB into the cmsg, and if
> that's the case then the fix is to linearlize the skb before the put_cmsg()
> or have a way to put a non-linear SKB into a cmsg.
I simply matched the conditions in __skb_tstamp_tx() which builds the
skb :
+ if (tsonly) {
+#ifdef CONFIG_INET
+ if ((sk->sk_tsflags & SOF_TIMESTAMPING_OPT_STATS) &&
+ sk->sk_protocol == IPPROTO_TCP &&
+ sk->sk_type == SOCK_STREAM)
+ skb = tcp_get_timestamping_opt_stats(sk);
+ else
+#endif
+ skb = alloc_skb(0, GFP_ATOMIC);
+ } else {
And note that I should have also used the #ifdef
A proper fix would be to find a bit in skb->cb[] to avoid duplicating
the test...
Back to linux.kernel | Previous | Next — Previous in thread | Find similar | Unroll thread
Re: net/udp: slab-out-of-bounds Read in udp_recvmsg Eric Dumazet <eric.dumazet@gmail.com> - 2017-03-15 17:20 +0100
Re: net/udp: slab-out-of-bounds Read in udp_recvmsg David Miller <davem@davemloft.net> - 2017-03-15 23:10 +0100
Re: net/udp: slab-out-of-bounds Read in udp_recvmsg Eric Dumazet <eric.dumazet@gmail.com> - 2017-03-15 23:50 +0100
csiph-web