All of lore.kernel.org
 help / color / mirror / Atom feed
From: Greg KH <gregkh@suse.de>
To: linux-kernel@vger.kernel.org, stable@kernel.org
Cc: Justin Forbes <jmforbes@linuxtx.org>,
	Zwane Mwaikambo <zwane@arm.linux.org.uk>,
	"Theodore Ts'o" <tytso@mit.edu>,
	Randy Dunlap <rdunlap@xenotime.net>,
	Dave Jones <davej@redhat.com>,
	Chuck Wolber <chuckw@quantumlinux.com>,
	Chris Wedgwood <reviews@ml.cw.f00f.org>,
	Michael Krufky <mkrufky@linuxtv.org>,
	Chuck Ebbert <cebbert@redhat.com>,
	Domenico Andreoli <cavokz@gmail.com>, Willy Tarreau <w@1wt.eu>,
	Rodrigo Rubira Branco <rbranco@la.checkpoint.com>,
	Jake Edge <jake@lwn.net>,
	torvalds@linux-foundation.org, akpm@linux-foundation.org,
	alan@lxorguk.ukuu.org.uk, James Chapman <jchapman@katalix.com>,
	"David S. Miller" <davem@davemloft.net>
Subject: [patch 4/9] l2tp: Fix potential memory corruption in pppol2tp_recvmsg()
Date: Fri, 25 Jul 2008 16:07:25 -0700	[thread overview]
Message-ID: <20080725230725.GE1612@suse.de> (raw)
In-Reply-To: <20080725230644.GA1612@suse.de>

[-- Attachment #1: 0004-l2tp-Fix-potential-memory-corruption-in-pppol2tp_re.patch --]
[-- Type: text/plain, Size: 1667 bytes --]

2.6.25-stable review patch.  If anyone has any objections, please let us
know.

------------------
From: James Chapman <jchapman@katalix.com>

[ Upstream commit 6b6707a50c7598a83820077393f8823ab791abf8 ]

This patch fixes a potential memory corruption in
pppol2tp_recvmsg(). If skb->len is bigger than the caller's buffer
length, memcpy_toiovec() will go into unintialized data on the kernel
heap, interpret it as an iovec and start modifying memory.

The fix is to change the memcpy_toiovec() call to
skb_copy_datagram_iovec() so that paged packets (rare for PPPOL2TP)
are handled properly. Also check that the caller's buffer is big
enough for the data and set the MSG_TRUNC flag if it is not so.

Reported-by: Ilja <ilja@netric.org>
Signed-off-by: James Chapman <jchapman@katalix.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>

---
 drivers/net/pppol2tp.c |   20 ++++++++++++--------
 1 file changed, 12 insertions(+), 8 deletions(-)

--- a/drivers/net/pppol2tp.c
+++ b/drivers/net/pppol2tp.c
@@ -783,14 +783,18 @@ static int pppol2tp_recvmsg(struct kiocb
 	err = 0;
 	skb = skb_recv_datagram(sk, flags & ~MSG_DONTWAIT,
 				flags & MSG_DONTWAIT, &err);
-	if (skb) {
-		err = memcpy_toiovec(msg->msg_iov, (unsigned char *) skb->data,
-				     skb->len);
-		if (err < 0)
-			goto do_skb_free;
-		err = skb->len;
-	}
-do_skb_free:
+	if (!skb)
+		goto end;
+
+	if (len > skb->len)
+		len = skb->len;
+	else if (len < skb->len)
+		msg->msg_flags |= MSG_TRUNC;
+
+	err = skb_copy_datagram_iovec(skb, 0, msg->msg_iov, len);
+	if (likely(err == 0))
+		err = len;
+
 	kfree_skb(skb);
 end:
 	return err;

-- 

  parent reply	other threads:[~2008-07-25 23:12 UTC|newest]

Thread overview: 15+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <20080725225425.193966072@mini.kroah.org>
2008-07-25 23:06 ` [patch 0/9] 2.6.25-stable review Greg KH
2008-07-25 23:07   ` [patch 1/9] hdlcdrv: Fix CRC calculation Greg KH
2008-07-25 23:07   ` [patch 2/9] ipv6: __KERNEL__ ifdef struct ipv6_devconf Greg KH
2008-07-25 23:07   ` [patch 3/9] ipv6: use timer pending Greg KH
2008-07-25 23:07   ` Greg KH [this message]
2008-07-25 23:07   ` [patch 5/9] net pppoe: Check packet length on all receive paths Greg KH
2008-07-25 23:07   ` [patch 6/9] pppoe: Unshare skb before anything else Greg KH
2008-07-25 23:07   ` [patch 7/9] raw: Restore /proc/net/raw correct behavior Greg KH
2008-07-25 23:07   ` [patch 8/9] xfrm: fix fragmentation for ipv4 xfrm tunnel Greg KH
2008-07-25 23:07   ` [patch 9/9] udplite: Protection against coverage value wrap-around Greg KH
2008-07-26  2:54   ` [patch 0/9] 2.6.25-stable review Grant Coady
2008-07-26  3:44     ` Greg KH
2008-07-26  4:07     ` Richard A Nelson
2008-07-26  5:08       ` [stable] " Greg KH
2008-07-26  6:27         ` Henrique de Moraes Holschuh

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20080725230725.GE1612@suse.de \
    --to=gregkh@suse.de \
    --cc=akpm@linux-foundation.org \
    --cc=alan@lxorguk.ukuu.org.uk \
    --cc=cavokz@gmail.com \
    --cc=cebbert@redhat.com \
    --cc=chuckw@quantumlinux.com \
    --cc=davej@redhat.com \
    --cc=davem@davemloft.net \
    --cc=jake@lwn.net \
    --cc=jchapman@katalix.com \
    --cc=jmforbes@linuxtx.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mkrufky@linuxtv.org \
    --cc=rbranco@la.checkpoint.com \
    --cc=rdunlap@xenotime.net \
    --cc=reviews@ml.cw.f00f.org \
    --cc=stable@kernel.org \
    --cc=torvalds@linux-foundation.org \
    --cc=tytso@mit.edu \
    --cc=w@1wt.eu \
    --cc=zwane@arm.linux.org.uk \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.