From: Vlad Yasevich <vyasevic@redhat.com>
To: Xin Long <lucien.xin@gmail.com>, network dev <netdev@vger.kernel.org>
Cc: mleitner@redhat.com, davem@davemloft.net
Subject: Re: [PATCH net] sctp: asconf's process should verify address parameter is in the beginning
Date: Mon, 24 Aug 2015 13:33:48 -0400 [thread overview]
Message-ID: <55DB557C.6090506@redhat.com> (raw)
In-Reply-To: <87d339ea910a3665c9376b6ba69b003af967c6d1.1440410878.git.lucien.xin@gmail.com>
On 08/24/2015 06:07 AM, Xin Long wrote:
> in sctp_process_asconf(), we get address parameter from the beginning of the
> addip params. but we never check if it's really there. if the addr param is not
> there, it still can pass sctp_verify_asconf(), then to be handled by
> sctp_process_asconf(), it will not be safe.
>
> so add a code in sctp_verify_asconf() to check the address parameter is in the
> beginning, or return false to send abort.
>
> Signed-off-by: Xin Long <lucien.xin@gmail.com>
> ---
> net/sctp/sm_make_chunk.c | 8 ++++++++
> 1 file changed, 8 insertions(+)
>
> diff --git a/net/sctp/sm_make_chunk.c b/net/sctp/sm_make_chunk.c
> index 0ee5ca7..a2a72d5 100644
> --- a/net/sctp/sm_make_chunk.c
> +++ b/net/sctp/sm_make_chunk.c
> @@ -3122,6 +3122,14 @@ bool sctp_verify_asconf(const struct sctp_association *asoc,
> union sctp_params param;
> bool addr_param_seen = false;
>
> + if(addr_param_needed){
> + /* Ensure the address parameter is in the beginning */
> + param.v = chunk->skb->data + sizeof(sctp_addiphdr_t);
> + if (param.p->type != SCTP_PARAM_IPV4_ADDRESS &&
> + param.p->type != SCTP_PARAM_IPV6_ADDRESS)
> + return false;
> + }
> +
Sorry, you can't do that directly without a lot more checks. The parameer
may be only only partial, or may not be there at all. You'd end up looking
at wrong mememory.
A better way would be to set the addr_param_seen only when looking at
the first parameter (addip_hdr.params).
-vlad
> sctp_walk_params(param, addip, addip_hdr.params) {
> size_t length = ntohs(param.p->length);
>
>
next prev parent reply other threads:[~2015-08-24 17:33 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2015-08-24 10:07 [PATCH net] sctp: asconf's process should verify address parameter is in the beginning Xin Long
2015-08-24 12:13 ` Sergei Shtylyov
2015-08-24 17:33 ` Vlad Yasevich [this message]
2015-08-25 12:28 ` lucien xin
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=55DB557C.6090506@redhat.com \
--to=vyasevic@redhat.com \
--cc=davem@davemloft.net \
--cc=lucien.xin@gmail.com \
--cc=mleitner@redhat.com \
--cc=netdev@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.