Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1601776
| From | David Miller <davem@davemloft.net> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | Re: net/udp: slab-out-of-bounds Read in udp_recvmsg |
| Date | 2017-03-15 23:10 +0100 |
| Message-ID | <tlphg-5w5-15@gated-at.bofh.it> (permalink) |
| References | <tljlw-1aZ-27@gated-at.bofh.it> <tljES-1xz-15@gated-at.bofh.it> <tljOy-1CE-21@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
From: Eric Dumazet <eric.dumazet@gmail.com>
Date: Wed, 15 Mar 2017 09:10:33 -0700
> @@ -692,12 +692,17 @@ void __sock_recv_timestamp(struct msghdr *msg, struct sock *sk,
> ktime_to_timespec_cond(shhwtstamps->hwtstamp, tss.ts + 2))
> empty = 0;
> if (!empty) {
> + unsigned int hlen = skb_headlen(skb);
> +
> put_cmsg(msg, SOL_SOCKET,
> SCM_TIMESTAMPING, sizeof(tss), &tss);
>
> - if (skb->len && (sk->sk_tsflags & SOF_TIMESTAMPING_OPT_STATS))
> + if (hlen &&
> + (sk->sk_tsflags & SOF_TIMESTAMPING_OPT_STATS) &&
> + sk->sk_protocol == IPPROTO_TCP &&
> + sk->sk_type == SOCK_STREAM)
> put_cmsg(msg, SOL_SOCKET, SCM_TIMESTAMPING_OPT_STATS,
> - skb->len, skb->data);
> + hlen, skb->data);
Hmmm, what is the true intention of SOF_TIMESTAMPING_OPT_STATS then? The
existing code seems to want to dump the entire SKB into the cmsg, and if
that's the case then the fix is to linearlize the skb before the put_cmsg()
or have a way to put a non-linear SKB into a cmsg.
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Re: net/udp: slab-out-of-bounds Read in udp_recvmsg Eric Dumazet <eric.dumazet@gmail.com> - 2017-03-15 17:20 +0100
Re: net/udp: slab-out-of-bounds Read in udp_recvmsg David Miller <davem@davemloft.net> - 2017-03-15 23:10 +0100
Re: net/udp: slab-out-of-bounds Read in udp_recvmsg Eric Dumazet <eric.dumazet@gmail.com> - 2017-03-15 23:50 +0100
csiph-web