From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1752042AbaGZPyp (ORCPT ); Sat, 26 Jul 2014 11:54:45 -0400 Received: from out1-smtp.messagingengine.com ([66.111.4.25]:33367 "EHLO out1-smtp.messagingengine.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751858AbaGZPyo (ORCPT ); Sat, 26 Jul 2014 11:54:44 -0400 X-Sasl-enc: KzKBTaF1EUto5FmhaKsrvQ35GKOIJoWT2n2apnKGX+Lk 1406390082 Message-ID: <1406390080.22881.75.camel@localhost> Subject: Re: net: socket: NULL ptr deref in sendmsg From: Hannes Frederic Sowa To: Andrey Ryabinin Cc: Andrey Ryabinin , Sasha Levin , "David S. Miller" , "netdev@vger.kernel.org" , LKML , Dave Jones , Eric Dumazet Date: Sat, 26 Jul 2014 17:54:40 +0200 In-Reply-To: References: <53C2FF3D.4030201@oracle.com> <53D2768E.2040902@samsung.com> <1406326508.13203.10.camel@localhost> Content-Type: text/plain; charset="UTF-8" X-Mailer: Evolution 3.10.4 (3.10.4-2.fc20) Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Sa, 2014-07-26 at 19:48 +0400, Andrey Ryabinin wrote: > 2014-07-26 2:15 GMT+04:00 Hannes Frederic Sowa : > > Otherwise I would just set msg_namelen = 0, too, and just not handle > > passed in NULL pointers to sockaddrs. > > > > I like that, how about such chage: > > diff --git a/net/compat.c b/net/compat.c > index 9a76eaf..bc8aeef 100644 > --- a/net/compat.c > +++ b/net/compat.c > @@ -85,7 +85,7 @@ int verify_compat_iovec(struct msghdr *kern_msg, > struct iovec *kern_iov, > { > int tot_len; > > - if (kern_msg->msg_namelen) { > + if (kern_msg->msg_name && kern_msg->msg_namelen) { > if (mode == VERIFY_READ) { > int err = move_addr_to_kernel(kern_msg->msg_name, > kern_msg->msg_namelen, > @@ -93,10 +93,11 @@ int verify_compat_iovec(struct msghdr *kern_msg, > struct iovec *kern_iov, > if (err < 0) > return err; > } > - if (kern_msg->msg_name) > - kern_msg->msg_name = kern_address; > - } else > + kern_msg->msg_name = kern_address; > + } else { > kern_msg->msg_name = NULL; > + kern_msg->msg_namelen = 0; > + } > > tot_len = iov_from_user_compat_to_kern(kern_iov, > (struct compat_iovec __user > *)kern_msg->msg_iov, > diff --git a/net/core/iovec.c b/net/core/iovec.c > index 827dd6b..e1ec45a 100644 > --- a/net/core/iovec.c > +++ b/net/core/iovec.c > @@ -39,7 +39,7 @@ int verify_iovec(struct msghdr *m, struct iovec > *iov, struct sockaddr_storage *a > { > int size, ct, err; > > - if (m->msg_namelen) { > + if (m->msg_name && m->msg_namelen) { > if (mode == VERIFY_READ) { > void __user *namep; > namep = (void __user __force *) m->msg_name; > @@ -48,10 +48,10 @@ int verify_iovec(struct msghdr *m, struct iovec > *iov, struct sockaddr_storage *a > if (err < 0) > return err; > } > - if (m->msg_name) > - m->msg_name = address; > + m->msg_name = address; > } else { > m->msg_name = NULL; > + m->msg_namelen = 0; > } > > size = m->msg_iovlen * sizeof(struct iovec); > > LGTM! Can you send a patch? Thanks, Hannes