From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-2.5 required=3.0 tests=DKIMWL_WL_HIGH,DKIM_SIGNED, DKIM_VALID,HEADER_FROM_DIFFERENT_DOMAINS,MAILING_LIST_MULTI,SPF_PASS, USER_AGENT_MUTT autolearn=ham autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id B5951C43381 for ; Tue, 12 Mar 2019 18:58:09 +0000 (UTC) Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by mail.kernel.org (Postfix) with ESMTP id 7EE3E214AF for ; Tue, 12 Mar 2019 18:58:09 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=default; t=1552417089; bh=U0eB1PfXl/MnHHi+ltIOyvDFHU6stdUbu6Y3jTTnZ0Q=; h=Date:From:To:Cc:Subject:References:In-Reply-To:List-ID:From; b=y09NKkN6dVgOFZ12RAaFJzAsm9x0l0Bply29zPx1rJsdME4n7Nh+JgP+U91pPFWtq 49F34T0GNyjLoT8hJNwtcapyRQzHNf4AQER0qbgldAHrm+l5G/dcXaaaWkhD7ms+jP t0JShaZQOPrXRwUtEYSsHRkuL71vOlIarHZuPQrc= Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1726606AbfCLS6J (ORCPT ); Tue, 12 Mar 2019 14:58:09 -0400 Received: from mail.kernel.org ([198.145.29.99]:46086 "EHLO mail.kernel.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1726490AbfCLS6J (ORCPT ); Tue, 12 Mar 2019 14:58:09 -0400 Received: from localhost (unknown [104.133.8.98]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPSA id 12BD12087C; Tue, 12 Mar 2019 18:58:08 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=default; t=1552417088; bh=U0eB1PfXl/MnHHi+ltIOyvDFHU6stdUbu6Y3jTTnZ0Q=; h=Date:From:To:Cc:Subject:References:In-Reply-To:From; b=dlwW5tKm81c3tiTeSRykkIPmMMreNr3+HptWlC0Pm7qTbnVGiwJyVPA0kYC1WLF9y vB8GWALAY0AzSb8vKuyhimay4tXPfzcgcrHI80leJcwGJDLIiVK1JHx/82S8IpTdaZ 9QyhMA2KAQhcYjB6P04X8fKMHeKWMknXRnPZagQ4= Date: Tue, 12 Mar 2019 11:58:06 -0700 From: Greg KH To: Zubin Mithra Cc: stable@vger.kernel.org, groeck@chromium.org, pablo@netfilter.org, kadlec@blackhole.kfki.hu, fw@strlen.de, sploving1@gmail.com Subject: Re: b301f2538759 ("netfilter: x_tables: enforce nul-terminated table name from getsockopt GET_ENTRIES") Message-ID: <20190312185806.GA15253@kroah.com> References: <20190312180752.GA162337@google.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20190312180752.GA162337@google.com> User-Agent: Mutt/1.11.3 (2019-02-01) Sender: stable-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: stable@vger.kernel.org On Tue, Mar 12, 2019 at 11:07:53AM -0700, Zubin Mithra wrote: > Hello, > > Syzkaller has triggered a stack OOB read when fuzzing a 4.4 kernel with the following stacktrace. > > Call Trace: > [] __dump_stack lib/dump_stack.c:15 [inline] > [] dump_stack+0xc1/0x124 lib/dump_stack.c:51 > [] print_address_description mm/kasan/report.c:199 [inline] > [] kasan_report_error mm/kasan/report.c:285 [inline] > [] kasan_report.part.2.cold.3+0x447/0x4ec mm/kasan/report.c:310 > [] kasan_report mm/kasan/report.c:328 [inline] > [] __asan_report_load1_noabort+0x2e/0x30 mm/kasan/report.c:328 > [] strnlen+0xc1/0xd0 lib/string.c:498 > [] string.isra.4+0x4c/0x250 lib/vsprintf.c:518 > [] vsnprintf+0x42a/0x18c0 lib/vsprintf.c:1904 > [] __request_module+0x153/0x7a0 kernel/kmod.c:146 > [] find_inlist_lock.constprop.15+0x111/0x210 net/bridge/netfilter/ebtables.c:347 > [] find_table_lock net/bridge/netfilter/ebtables.c:356 [inline] > [] do_ebt_get_ctl+0x152/0x570 net/bridge/netfilter/ebtables.c:1531 > [] nf_sockopt net/netfilter/nf_sockopt.c:103 [inline] > [] nf_getsockopt+0x75/0xd0 net/netfilter/nf_sockopt.c:121 > [] ip_getsockopt+0x12d/0x170 net/ipv4/ip_sockglue.c:1533 > [] tcp_getsockopt+0x8d/0xe0 net/ipv4/tcp.c:3040 > [] sock_common_getsockopt+0x9f/0xe0 net/core/sock.c:2652 > [] SYSC_getsockopt net/socket.c:1811 [inline] > [] SyS_getsockopt+0x14d/0x230 net/socket.c:1793 > [] tracesys_phase2+0x90/0x95 > > Could the following patch be applied to v4.4.y? The patch is present in v4.9.y. > * b301f2538759 ("netfilter: x_tables: enforce nul-terminated table name from getsockopt GET_ENTRIES") > > Tests run: > * Chrome OS tryjobs > * Syzkaller reproducer Now queued up, thanks. greg k-h