b.a.t.m.a.n.lists.open-mesh.org archive mirror
 help / color / mirror / Atom feed
From: Sven Eckelmann <sven.eckelmann@gmx.de>
To: greg@kroah.com
Cc: b.a.t.m.a.n@lists.open-mesh.org, Marek Lindner <lindner_marek@yahoo.de>
Subject: [B.A.T.M.A.N.] [PATCH 5/7] Staging: batman-adv: protect against ogm packet overflow by checking table length
Date: Tue, 19 Oct 2010 11:59:13 +0200	[thread overview]
Message-ID: <1287482355-16319-6-git-send-email-sven.eckelmann@gmx.de> (raw)
In-Reply-To: <1287482355-16319-1-git-send-email-sven.eckelmann@gmx.de>

From: Marek Lindner <lindner_marek@yahoo.de>

Reported-by: Sam Yeung <sam.cwyeung@gmail.com>
Signed-off-by: Marek Lindner <lindner_marek@yahoo.de>
Signed-off-by: Sven Eckelmann <sven.eckelmann@gmx.de>
---
 drivers/staging/batman-adv/translation-table.c |    9 +++++++--
 1 files changed, 7 insertions(+), 2 deletions(-)

diff --git a/drivers/staging/batman-adv/translation-table.c b/drivers/staging/batman-adv/translation-table.c
index 12b2325..681ccbd 100644
--- a/drivers/staging/batman-adv/translation-table.c
+++ b/drivers/staging/batman-adv/translation-table.c
@@ -59,6 +59,7 @@ void hna_local_add(struct net_device *soft_iface, uint8_t *addr)
 	struct hna_global_entry *hna_global_entry;
 	struct hashtable_t *swaphash;
 	unsigned long flags;
+	int required_bytes;
 
 	spin_lock_irqsave(&bat_priv->hna_lhash_lock, flags);
 	hna_local_entry =
@@ -74,8 +75,12 @@ void hna_local_add(struct net_device *soft_iface, uint8_t *addr)
 	/* only announce as many hosts as possible in the batman-packet and
 	   space in batman_packet->num_hna That also should give a limit to
 	   MAC-flooding. */
-	if ((bat_priv->num_local_hna + 1 > (ETH_DATA_LEN - BAT_PACKET_LEN)
-								/ ETH_ALEN) ||
+	required_bytes = (bat_priv->num_local_hna + 1) * ETH_ALEN;
+	required_bytes += BAT_PACKET_LEN;
+
+	if ((required_bytes > ETH_DATA_LEN) ||
+	    (atomic_read(&bat_priv->aggregation_enabled) &&
+	     required_bytes > MAX_AGGREGATION_BYTES) ||
 	    (bat_priv->num_local_hna + 1 > 255)) {
 		bat_dbg(DBG_ROUTES, bat_priv,
 			"Can't add new local hna entry (%pM): "
-- 
1.7.2.3


  parent reply	other threads:[~2010-10-19  9:59 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2010-10-19  9:59 [B.A.T.M.A.N.] Staging: batman-adv for 2.6.37 (4) Sven Eckelmann
2010-10-19  9:59 ` [B.A.T.M.A.N.] [PATCH 1/7] Staging: batman-adv: Add hash recommendations to TODO Sven Eckelmann
2010-10-19  9:59 ` [B.A.T.M.A.N.] [PATCH 2/7] Staging: batman-adv: Don't dereference unchecked incoming soft_iface Sven Eckelmann
2010-10-19  9:59 ` [B.A.T.M.A.N.] [PATCH 3/7] Staging: batman-adv: Fix resizing of broadcast seqno buffers on if deletion Sven Eckelmann
2010-10-19  9:59 ` [B.A.T.M.A.N.] [PATCH 4/7] Staging: batman-adv: document fragmentation sysfs API Sven Eckelmann
2010-10-19  9:59 ` Sven Eckelmann [this message]
2010-10-19  9:59 ` [B.A.T.M.A.N.] [PATCH 6/7] Staging: batman-adv: fix crash when new OGM is generated Sven Eckelmann
2010-10-19  9:59 ` [B.A.T.M.A.N.] [PATCH 7/7] Staging: batman-adv: process OGMs bigger than MAX_AGGREGATION_BYTES Sven Eckelmann

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1287482355-16319-6-git-send-email-sven.eckelmann@gmx.de \
    --to=sven.eckelmann@gmx.de \
    --cc=b.a.t.m.a.n@lists.open-mesh.org \
    --cc=greg@kroah.com \
    --cc=lindner_marek@yahoo.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).