From mboxrd@z Thu Jan 1 00:00:00 1970 From: David Miller Subject: Re: [PATCH net] tcp: fix TCP_REPAIR_QUEUE bound checking Date: Tue, 01 May 2018 12:26:56 -0400 (EDT) Message-ID: <20180501.122656.553682730004783997.davem@davemloft.net> References: <20180430015520.92179-1-edumazet@google.com> Mime-Version: 1.0 Content-Type: Text/Plain; charset=us-ascii Content-Transfer-Encoding: 7bit Cc: netdev@vger.kernel.org, eric.dumazet@gmail.com, xemul@parallels.com To: edumazet@google.com Return-path: Received: from shards.monkeyblade.net ([184.105.139.130]:46986 "EHLO shards.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1755188AbeEAQ06 (ORCPT ); Tue, 1 May 2018 12:26:58 -0400 In-Reply-To: <20180430015520.92179-1-edumazet@google.com> Sender: netdev-owner@vger.kernel.org List-ID: From: Eric Dumazet Date: Sun, 29 Apr 2018 18:55:20 -0700 > syzbot is able to produce a nasty WARN_ON() in tcp_verify_left_out() > with following C-repro : > > socket(PF_INET, SOCK_STREAM, IPPROTO_IP) = 3 > setsockopt(3, SOL_TCP, TCP_REPAIR, [1], 4) = 0 > setsockopt(3, SOL_TCP, TCP_REPAIR_QUEUE, [-1], 4) = 0 > bind(3, {sa_family=AF_INET, sin_port=htons(20002), sin_addr=inet_addr("0.0.0.0")}, 16) = 0 > sendto(3, "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0"..., > 1242, MSG_FASTOPEN, {sa_family=AF_INET, sin_port=htons(20002), sin_addr=inet_addr("127.0.0.1")}, 16) = 1242 > setsockopt(3, SOL_TCP, TCP_REPAIR_WINDOW, "\4\0\0@+\205\0\0\377\377\0\0\377\377\377\177\0\0\0\0", 20) = 0 > writev(3, [{"\270", 1}], 1) = 1 > setsockopt(3, SOL_TCP, TCP_REPAIR_OPTIONS, "\10\0\0\0\0\0\0\0\0\0\0\0|\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0"..., 386) = 0 > writev(3, [{"\210v\r[\226\320t\231qwQ\204\264l\254\t\1\20\245\214p\350H\223\254;\\\37\345\307p$"..., 3144}], 1) = 3144 > > The 3rd system call looks odd : > setsockopt(3, SOL_TCP, TCP_REPAIR_QUEUE, [-1], 4) = 0 > > This patch makes sure bound checking is using an unsigned compare. > > Fixes: ee9952831cfd ("tcp: Initial repair mode") > Signed-off-by: Eric Dumazet > Reported-by: syzbot Ouch. Applied and queued up for -stable, thanks Eric.