From: Herbert Xu <herbert@gondor.apana.org.au>
To: "David S. Miller" <davem@davemloft.net>, netdev@vger.kernel.org
Cc: Roland Dreier <roland@purestorage.com>
Subject: arp_hash
Date: Sun, 22 Mar 2015 22:42:04 +1100 [thread overview]
Message-ID: <20150322114204.GA5010@gondor.apana.org.au> (raw)
Hi Dave:
While googling I found the 2011 discussion on changing the arp_hash
function. I must say that I'm not really impressed by the new
function that replaced jhash :)
u32 key = *(const u32 *)pkey;
u32 val = key ^ hash32_ptr(dev);
return val * hash_rnd[0];
Here pkey is the IP address (controllable by the attacker). It
gets xored with the device pointer hash, which on x86-64 looks
like (0xffffffff ^ ptr) where ptr is a 32-bit value. As ptr
must be aligned to at least 8 bytes (I think 16 is probably required
but I haven't checked), that means the bottom three bits of ptr
are 000 and hence the bottom three bits of hash32_ptr(dev) are
always 111.
So the attacker just has to use only addresses with the bottom
3 bits set to 111 and voila, the bottom three bits of val are
always 000. So you've just cut down your search space by a factor
of 8. If my assumption above of the 16-byte alignment is correct
then you can cut it down by a factor of 16.
If the attacker can somehow get the pointer value of the device
then all is lost since they could set any number of the low bits
of val to zero.
Cheers,
--
Email: Herbert Xu <herbert@gondor.apana.org.au>
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt
next reply other threads:[~2015-03-22 11:42 UTC|newest]
Thread overview: 19+ messages / expand[flat|nested] mbox.gz Atom feed top
2015-03-22 11:42 Herbert Xu [this message]
2015-03-22 12:56 ` arp_hash Eric Dumazet
2015-03-22 16:57 ` arp_hash David Miller
2015-03-22 21:21 ` arp_hash Herbert Xu
2015-03-22 21:56 ` arp_hash Herbert Xu
2015-03-22 22:51 ` arp_hash Herbert Xu
2015-03-22 23:22 ` arp_hash Herbert Xu
2015-03-22 23:35 ` arp_hash Herbert Xu
2015-03-23 10:58 ` arp_hash Herbert Xu
2015-03-22 22:58 ` arp_hash David Miller
2015-03-22 23:08 ` arp_hash Herbert Xu
2015-03-22 23:50 ` arp_hash David Miller
2015-03-22 23:53 ` arp_hash Herbert Xu
2015-03-22 16:54 ` arp_hash David Miller
2015-03-22 21:34 ` arp_hash Herbert Xu
2015-03-22 22:57 ` arp_hash David Miller
2015-03-22 23:42 ` arp_hash Herbert Xu
2015-03-22 23:53 ` arp_hash David Miller
2015-03-23 11:01 ` arp_hash Herbert Xu
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20150322114204.GA5010@gondor.apana.org.au \
--to=herbert@gondor.apana.org.au \
--cc=davem@davemloft.net \
--cc=netdev@vger.kernel.org \
--cc=roland@purestorage.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox