[PATCH] net: fix potential infoleak in rds_inc_info_copy

Subsystems: networking [general], rds - reliable datagram sockets, the rest

STALE3746d

2 messages, 2 authors, 2016-06-02 · open the first message on its own page

[PATCH] net: fix potential infoleak in rds_inc_info_copy

From: Kangjie Lu <hidden>
Date: 2016-06-01 16:11:27

The last field "flags" of object "minfo" is not initialized.
Copying this object out may leak kernel stack data.
Assign 0 to it to avoid leak.

Signed-off-by: Kangjie Lu <redacted>
---
 net/rds/recv.c | 2 ++
 1 file changed, 2 insertions(+)
diff --git a/net/rds/recv.c b/net/rds/recv.c
index c0be1ec..8413f6c 100644
--- a/net/rds/recv.c
+++ b/net/rds/recv.c
@@ -561,5 +561,7 @@ void rds_inc_info_copy(struct rds_incoming *inc,
 		minfo.fport = inc->i_hdr.h_dport;
 	}
 
+	minfo.flags = 0;
+
 	rds_info_copy(iter, &minfo, sizeof(minfo));
 }
-- 
2.7.4

Re: [PATCH] net: fix potential infoleak in rds_inc_info_copy

From: David Miller <davem@davemloft.net>
Date: 2016-06-02 06:32:52

From: Kangjie Lu <redacted>
Date: Wed,  1 Jun 2016 12:11:16 -0400
The last field "flags" of object "minfo" is not initialized.
Copying this object out may leak kernel stack data.
Assign 0 to it to avoid leak.

Signed-off-by: Kangjie Lu <redacted>
The correct subsystem prefix is "rds: ".  Please resubmit this patch
with your Subject corrected thusly.

Thanks.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help