Thread (6 messages) flat view 6 messages, 3 authors, 2011-11-29

Re: [PATCH] sctp: integer overflow in sctp_auth_create_key()

From: Xi Wang <xi.wang@gmail.com>
Date: 2011-11-29 19:24:07
Also in: linux-sctp, lkml

Possibly related (same subject, not in this thread)

Thanks for clarifying this!

I will leave the check there and incorporate your comments into a new patch.

- xi

On Nov 29, 2011, at 10:03 AM, Vladislav Yasevich wrote:
That should be ok as well.  There is an overflow guard in the api
entry point so that should guard against overflows from user space.

On the network end I miscalculated a little.  The key is actually made up
of user_key (1 short) + 2 * key_vector (3 shorts) for a total of 7*MAX_USHORT;
however, that still will not overflow 32 bits.

-vlad
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help