linux-kernel.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* [PATCH AUTOSEL 4.14 01/61] xfrm: Validate address prefix lengths in the xfrm selector.
@ 2018-10-16  4:13 Sasha Levin
  2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 02/61] xfrm6: call kfree_skb when skb is toobig Sasha Levin
                   ` (59 more replies)
  0 siblings, 60 replies; 61+ messages in thread
From: Sasha Levin @ 2018-10-16  4:13 UTC (permalink / raw)
  To: stable, linux-kernel; +Cc: Steffen Klassert, Sasha Levin

From: Steffen Klassert <steffen.klassert@secunet.com>

[ Upstream commit 07bf7908950a8b14e81aa1807e3c667eab39287a ]

We don't validate the address prefix lengths in the xfrm
selector we got from userspace. This can lead to undefined
behaviour in the address matching functions if the prefix
is too big for the given address family. Fix this by checking
the prefixes and refuse SA/policy insertation when a prefix
is invalid.

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Reported-by: Air Icy <icytxw@gmail.com>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/xfrm/xfrm_user.c | 12 ++++++++++++
 1 file changed, 12 insertions(+)

diff --git a/net/xfrm/xfrm_user.c b/net/xfrm/xfrm_user.c
index 5554d28a32eb..4292347bf45e 100644
--- a/net/xfrm/xfrm_user.c
+++ b/net/xfrm/xfrm_user.c
@@ -151,10 +151,16 @@ static int verify_newsa_info(struct xfrm_usersa_info *p,
 	err = -EINVAL;
 	switch (p->family) {
 	case AF_INET:
+		if (p->sel.prefixlen_d > 32 || p->sel.prefixlen_s > 32)
+			goto out;
+
 		break;
 
 	case AF_INET6:
 #if IS_ENABLED(CONFIG_IPV6)
+		if (p->sel.prefixlen_d > 128 || p->sel.prefixlen_s > 128)
+			goto out;
+
 		break;
 #else
 		err = -EAFNOSUPPORT;
@@ -1353,10 +1359,16 @@ static int verify_newpolicy_info(struct xfrm_userpolicy_info *p)
 
 	switch (p->sel.family) {
 	case AF_INET:
+		if (p->sel.prefixlen_d > 32 || p->sel.prefixlen_s > 32)
+			return -EINVAL;
+
 		break;
 
 	case AF_INET6:
 #if IS_ENABLED(CONFIG_IPV6)
+		if (p->sel.prefixlen_d > 128 || p->sel.prefixlen_s > 128)
+			return -EINVAL;
+
 		break;
 #else
 		return  -EAFNOSUPPORT;
-- 
2.17.1


^ permalink raw reply related	[flat|nested] 61+ messages in thread

end of thread, other threads:[~2018-10-16  4:28 UTC | newest]

Thread overview: 61+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2018-10-16  4:13 [PATCH AUTOSEL 4.14 01/61] xfrm: Validate address prefix lengths in the xfrm selector Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 02/61] xfrm6: call kfree_skb when skb is toobig Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 03/61] xfrm: reset transport header back to network header after all input transforms ahave been applied Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 04/61] xfrm: reset crypto_done when iterating over multiple input xfrms Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 05/61] mac80211: Always report TX status Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 06/61] cfg80211: reg: Init wiphy_idx in regulatory_hint_core() Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 07/61] mac80211: fix pending queue hang due to TX_DROP Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 08/61] cfg80211: Address some corner cases in scan result channel updating Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 09/61] mac80211: TDLS: fix skb queue/priority assignment Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 10/61] mac80211: fix TX status reporting for ieee80211s Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 11/61] xfrm: Fix NULL pointer dereference when skb_dst_force clears the dst_entry Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 12/61] ARM: 8799/1: mm: fix pci_ioremap_io() offset check Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 13/61] xfrm: validate template mode Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 14/61] netfilter: bridge: Don't sabotage nf_hook calls from an l3mdev Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 15/61] arm64: hugetlb: Fix handling of young ptes Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 16/61] ARM: dts: BCM63xx: Fix incorrect interrupt specifiers Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 17/61] net: macb: Clean 64b dma addresses if they are not detected Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 18/61] net: hns: fix for unmapping problem when SMMU is on Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 19/61] soc: fsl: qbman: qman: avoid allocating from non existing gen_pool Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 20/61] soc: fsl: qe: Fix copy/paste bug in ucc_get_tdm_sync_shift() Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 21/61] nl80211: Fix possible Spectre-v1 for NL80211_TXRATE_HT Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 22/61] mac80211_hwsim: do not omit multicast announce of first added radio Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 23/61] Bluetooth: SMP: fix crash in unpairing Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 24/61] pxa168fb: prepare the clock Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 25/61] qed: Avoid implicit enum conversion in qed_set_tunn_cls_info Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 26/61] qed: Fix mask parameter in qed_vf_prep_tunn_req_tlv Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 27/61] qed: Avoid implicit enum conversion in qed_roce_mode_to_flavor Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 28/61] bonding: pass link-local packets to bonding master also Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 29/61] bonding: avoid possible dead-lock Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 30/61] qed: Avoid constant logical operation warning in qed_vf_pf_acquire Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 31/61] qed: Avoid implicit enum conversion in qed_iwarp_parse_rx_pkt Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 32/61] bnxt_en: Fix TX timeout during netpoll Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 33/61] nl80211: Fix possible Spectre-v1 for CQM RSSI thresholds Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 34/61] asix: Check for supported Wake-on-LAN modes Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 35/61] ax88179_178a: " Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 36/61] lan78xx: " Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 37/61] sr9800: " Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 38/61] r8152: Check for supported Wake-on-LAN Modes Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 39/61] smsc75xx: Check for Wake-on-LAN modes Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 40/61] smsc95xx: " Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 41/61] qlcnic: fix Tx descriptor corruption on 82xx devices Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 42/61] i2c: i2c-scmi: fix for i2c_smbus_write_block_data Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 43/61] cfg80211: fix use-after-free in reg_process_hint() Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 44/61] net/mlx5: E-Switch, Fix out of bound access when setting vport rate Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 45/61] net/mlx5e: Set vlan masks for all offloaded TC rules Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 46/61] perf/core: Fix perf_pmu_unregister() locking Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 47/61] perf/ring_buffer: Prevent concurent ring buffer access Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 48/61] perf/x86/intel/uncore: Fix PCI BDF address of M3UPI on SKX Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 49/61] perf/x86/amd/uncore: Set ThreadMask and SliceMask for L3 Cache perf events Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 50/61] net: fec: fix rare tx timeout Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 51/61] declance: Fix continuation with the adapter identification message Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 52/61] nfp: avoid soft lockups under control message storm Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 53/61] bonding: fix warning message Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 54/61] net: qualcomm: rmnet: Skip processing loopback packets Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 55/61] locking/ww_mutex: Fix runtime warning in the WW mutex selftest Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 56/61] net/usb: cancel pending work when unbinding smsc75xx Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 57/61] be2net: don't flip hw_features when VXLANs are added/deleted Sasha Levin
2018-10-16  4:14 ` [PATCH AUTOSEL 4.14 58/61] net: cxgb3_main: fix a missing-check bug Sasha Levin
2018-10-16  4:14 ` [PATCH AUTOSEL 4.14 59/61] yam: " Sasha Levin
2018-10-16  4:14 ` [PATCH AUTOSEL 4.14 60/61] ocfs2: fix crash in ocfs2_duplicate_clusters_by_page() Sasha Levin
2018-10-16  4:14 ` [PATCH AUTOSEL 4.14 61/61] mm/vmstat.c: fix outdated vmstat_text Sasha Levin

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).