Thread (46 messages) 46 messages, 5 authors, 2019-02-25

Re: [PATCH] NETWORKING: avoid use IPCB in cipso_v4_error

From: David Miller <davem@davemloft.net>
Date: 2019-02-15 20:00:12
Also in: netdev

From: Paul Moore <paul@paul-moore.com>
Date: Fri, 15 Feb 2019 14:02:31 -0500
On Thu, Feb 14, 2019 at 11:43 AM David Miller [off-list ref] wrote:
quoted
From: Nazarov Sergey <redacted>
Date: Tue, 12 Feb 2019 18:10:03 +0300
quoted
Since cipso_v4_error might be called from different network stack layers, we can't safely use icmp_send there.
icmp_send copies IP options with ip_option_echo, which uses IPCB to take access to IP header compiled data.
But after commit 971f10ec ("tcp: better TCP_SKB_CB layout to reduce cache line misses"), IPCB can't be used
above IP layer.
This patch fixes the problem by creating in cipso_v4_error a local copy of compiled IP options and using it with
introduced __icmp_send function. This looks some overloaded, but in quite rare error conditions only.

The original discussion is here:
https://lore.kernel.org/linux-security-module/16659801547571984@sas1-890ba5c2334a.qloud-c.yandex.net/ (local)

Signed-off-by: Sergey Nazarov <redacted>
This problem is not unique to Cipso, net/atm/clip.c's error handler
has the same exact issue.

I didn't scan more of the tree, there are probably a couple more
locations as well.
David, are you happy with Sergey's solution as a fix for this?

If so, would you prefer a respin of this patch to apply the to the
other broken callers (e.g. net/atm/clip.c), or would you rather merge
this patch and deal with the other callers in separate patches?
I'd like the other broken callers to be handled.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help