Thread (4 messages) flat view 4 messages, 4 authors, 2017-03-02

Re: [PATCH v4] net: don't call strlen() on the user buffer in packet_bind_spkt()

From: Cong Wang <hidden>
Date: 2017-03-02 05:22:40
Also in: lkml

On Wed, Mar 1, 2017 at 3:57 AM, Alexander Potapenko [off-list ref] wrote:
This happens because addr.sa_data copied from the userspace is not
zero-terminated, and copying it with strlcpy() in packet_bind_spkt()
results in calling strlen() on the kernel copy of that non-terminated
buffer.
Very similar to

commit b301f2538759933cf9ff1f7c4f968da72e3f0757
Author: Pablo Neira Ayuso [off-list ref]
Date:   Thu Mar 24 21:29:53 2016 +0100

    netfilter: x_tables: enforce nul-terminated table name from
getsockopt GET_ENTRIES
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help