Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1601776

Re: net/udp: slab-out-of-bounds Read in udp_recvmsg

From David Miller <davem@davemloft.net>
Newsgroups linux.kernel
Subject Re: net/udp: slab-out-of-bounds Read in udp_recvmsg
Date 2017-03-15 23:10 +0100
Message-ID <tlphg-5w5-15@gated-at.bofh.it> (permalink)
References <tljlw-1aZ-27@gated-at.bofh.it> <tljES-1xz-15@gated-at.bofh.it> <tljOy-1CE-21@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


From: Eric Dumazet <eric.dumazet@gmail.com>
Date: Wed, 15 Mar 2017 09:10:33 -0700

> @@ -692,12 +692,17 @@ void __sock_recv_timestamp(struct msghdr *msg, struct sock *sk,
>  	    ktime_to_timespec_cond(shhwtstamps->hwtstamp, tss.ts + 2))
>  		empty = 0;
>  	if (!empty) {
> +		unsigned int hlen = skb_headlen(skb);
> +
>  		put_cmsg(msg, SOL_SOCKET,
>  			 SCM_TIMESTAMPING, sizeof(tss), &tss);
>  
> -		if (skb->len && (sk->sk_tsflags & SOF_TIMESTAMPING_OPT_STATS))
> +		if (hlen &&
> +		    (sk->sk_tsflags & SOF_TIMESTAMPING_OPT_STATS) &&
> +		    sk->sk_protocol == IPPROTO_TCP &&
> +		    sk->sk_type == SOCK_STREAM)
>  			put_cmsg(msg, SOL_SOCKET, SCM_TIMESTAMPING_OPT_STATS,
> -				 skb->len, skb->data);
> +				 hlen, skb->data);

Hmmm, what is the true intention of SOF_TIMESTAMPING_OPT_STATS then?  The
existing code seems to want to dump the entire SKB into the cmsg, and if
that's the case then the fix is to linearlize the skb before the put_cmsg()
or have a way to put a non-linear SKB into a cmsg.

Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Re: net/udp: slab-out-of-bounds Read in udp_recvmsg Eric Dumazet <eric.dumazet@gmail.com> - 2017-03-15 17:20 +0100
  Re: net/udp: slab-out-of-bounds Read in udp_recvmsg David Miller <davem@davemloft.net> - 2017-03-15 23:10 +0100
    Re: net/udp: slab-out-of-bounds Read in udp_recvmsg Eric Dumazet <eric.dumazet@gmail.com> - 2017-03-15 23:50 +0100

csiph-web