netdev.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* [PATCH] 8 bytes kernel memory disclosure in AppleTalk getsockname.
@ 2009-08-26 11:12 Clement LECIGNE
  2009-08-26 12:01 ` Tetsuo Handa
  2009-08-26 12:35 ` Eric Dumazet
  0 siblings, 2 replies; 5+ messages in thread
From: Clement LECIGNE @ 2009-08-26 11:12 UTC (permalink / raw)
  To: linux-kernel; +Cc: netdev

Hi,

In function atalk_getname(), sockaddr_at is returned in userland without
zero'ing the "char sat_zero[8]" field. This bug allows user to display 8
bytes leaked from the kernel stack.

Here is a patch that zero the whole sockaddr_at structure before
processing it. It should fix this bug.

Signed-off-by: Clément Lecigne <clement.lecigne@netasq.com>
--- linux/net/appletalk/ddp.c	2009-08-26 11:35:59.000000000 +0200
+++ linux/net/appletalk/ddp.c	2009-08-26 11:36:30.000000000 +0200
@@ -1241,6 +1241,8 @@ static int atalk_getname(struct socket *
 		if (atalk_autobind(sk) < 0)
 			return -ENOBUFS;
 
+	memset(&sat, 0, sizeof(struct sockaddr_at));
+
 	*uaddr_len = sizeof(struct sockaddr_at);
 
 	if (peer) {

-- 
Clément LECIGNE,
-Only one remote hole in the default install, in more than 10 years!<br>
+Only two remote holes in the default install, in more than 10 years!<br>

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2009-08-26 12:40 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2009-08-26 11:12 [PATCH] 8 bytes kernel memory disclosure in AppleTalk getsockname Clement LECIGNE
2009-08-26 12:01 ` Tetsuo Handa
2009-08-26 12:38   ` Eric Dumazet
2009-08-26 12:35 ` Eric Dumazet
2009-08-26 12:39   ` Clement LECIGNE

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).