Thread (70 messages) 70 messages, 9 authors, 2019-01-13

Re: [PATCH V4 5/6] net: maclorawan: Implement maclorawan class module

From: Alan Cox <hidden>
Date: 2018-12-04 20:45:48
Also in: lkml, netdev

quoted hunk ↗ jump to hunk
+void
+lrw_parse_frame(struct lrw_session *ss, struct sk_buff *skb)
+{
+	struct lrw_fhdr *fhdr = &ss->rx_fhdr;
+	__le16 *p_fcnt;
+
+	pr_debug("%s: %s\n", LORAWAN_MODULE_NAME, __func__);
+
+	/* Get message type */
+	fhdr->mtype = skb->data[0];
+	skb_pull(skb, LRW_MHDR_LEN);
This does not seem robust. There is no point at which you actually check
the message size is valid etc
quoted hunk ↗ jump to hunk
+	fhdr->fopts_len = fhdr->fctrl & 0xF;
+	if (fhdr->fopts_len > 0) {
+		memcpy(fhdr->fopts, skb->data, fhdr->fopts_len);
+		skb_pull(skb, fhdr->fopts_len);
+	}
In fact you appear to copy random kernel memory into a buffer
quoted hunk ↗ jump to hunk
+
+	/* TODO: Parse frame options */
+
+	/* Remove message integrity code */
+	skb_trim(skb, skb->len - LRW_MIC_LEN);
and then try and trim the buffer to a negative size ?

Alan

_______________________________________________
linux-arm-kernel mailing list
linux-arm-kernel@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/linux-arm-kernel
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help