From: Nicolas Bareil <nico@chdir.org>
To: netdev@vger.kernel.org
Subject: [BUG] before() integer overflow
Date: Tue, 05 Aug 2008 19:19:18 +0200 [thread overview]
Message-ID: <87y73bqt0p.fsf@chdir.org> (raw)
Hello!
In include/net/tcp.h, the before() function is defined like this :
241 /*
242 * The next routines deal with comparing 32 bit unsigned ints
243 * and worry about wraparound (automatic with unsigned arithmetic).
244 */
245
246 static inline int before(__u32 seq1, __u32 seq2)
247 {
248 return (__s32)(seq1-seq2) < 0;
249 }
250 #define after(seq2, seq1) before(seq1, seq2)
If seq1 = 0xffffff and seq2 = 0 (so seq1 > seq2), the difference is
equal to 0xffffff, or -1 as a 32 bits signed number.
=> before() will return true instead of false.
It's not really a big deal[1], but I didn't understand why my invalid
packets were accepted when playing with Netfilter code.
If I'm not wrong, a trivial patch could be :
diff --git a/include/net/tcp.h b/include/net/tcp.h
index 8983386..2b01227 100644
--- a/include/net/tcp.h
+++ b/include/net/tcp.h
@@ -248,7 +248,7 @@ extern int tcp_memory_pressure;
static inline int before(__u32 seq1, __u32 seq2)
{
- return (__s32)(seq1-seq2) < 0;
+ return ((__u64)seq1-seq2) < 0;
}
#define after(seq2, seq1) before(seq1, seq2)
Thanks
Footnotes:
[1] The TCP sequence number space is divided by two, now on 31 bits,
phear! :)
--
Nicolas Bareil http://chdir.org/~nico/
OpenPGP=0xAE4F7057 Fingerprint=34DB22091049FB2F33E6B71580F314DAAE4F7057
next reply other threads:[~2008-08-05 17:20 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2008-08-05 17:19 Nicolas Bareil [this message]
2008-08-05 17:40 ` [BUG] before() integer overflow Ben Hutchings
2008-08-05 17:51 ` David Stevens
2008-08-05 18:24 ` Nicolas Bareil
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=87y73bqt0p.fsf@chdir.org \
--to=nico@chdir.org \
--cc=netdev@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.