[PATCH] rds: fix an infoleak in rds_inc_info_copy

Subsystems: networking [general], rds - reliable datagram sockets, the rest

STALE3715d

3 messages, 3 authors, 2016-06-03 · open the first message on its own page

[PATCH] rds: fix an infoleak in rds_inc_info_copy

From: Kangjie Lu <hidden>
Date: 2016-06-02 08:11:34

The last field "flags" of object "minfo" is not initialized.
Copying this object out may leak kernel stack data.
Assign 0 to it to avoid leak.

Signed-off-by: Kangjie Lu <redacted>
---
 net/rds/recv.c | 2 ++
 1 file changed, 2 insertions(+)
diff --git a/net/rds/recv.c b/net/rds/recv.c
index c0be1ec..8413f6c 100644
--- a/net/rds/recv.c
+++ b/net/rds/recv.c
@@ -561,5 +561,7 @@ void rds_inc_info_copy(struct rds_incoming *inc,
 		minfo.fport = inc->i_hdr.h_dport;
 	}
 
+	minfo.flags = 0;
+
 	rds_info_copy(iter, &minfo, sizeof(minfo));
 }
-- 
2.7.4

Re: [PATCH] rds: fix an infoleak in rds_inc_info_copy

From: Santosh Shilimkar <hidden>
Date: 2016-06-02 15:25:19

On 6/2/2016 1:11 AM, Kangjie Lu wrote:
The last field "flags" of object "minfo" is not initialized.
Copying this object out may leak kernel stack data.
Assign 0 to it to avoid leak.

Signed-off-by: Kangjie Lu <redacted>
---
 net/rds/recv.c | 2 ++
 1 file changed, 2 insertions(+)
Acked-by: Santosh Shilimkar <redacted>

Re: [PATCH] rds: fix an infoleak in rds_inc_info_copy

From: David Miller <davem@davemloft.net>
Date: 2016-06-03 04:33:08

From: Kangjie Lu <redacted>
Date: Thu,  2 Jun 2016 04:11:20 -0400
The last field "flags" of object "minfo" is not initialized.
Copying this object out may leak kernel stack data.
Assign 0 to it to avoid leak.

Signed-off-by: Kangjie Lu <redacted>
Applied.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help