[PATCH net] net: rtnetlink: fix info leak in RTM_GETSTATS call

Subsystems: networking [general], the rest

STALE3238d

3 messages, 3 authors, 2017-10-03 · open the first message on its own page

[PATCH net] net: rtnetlink: fix info leak in RTM_GETSTATS call

From: Nikolay Aleksandrov <hidden>
Date: 2017-10-03 10:22:21

When RTM_GETSTATS was added the fields of its header struct were not all
initialized when returning the result thus leaking 4 bytes of information
to user-space per rtnl_fill_statsinfo call, so initialize them now. Thanks
to Alexander Potapenko for the detailed report and bisection.

Reported-by: Alexander Potapenko <glider@google.com>
Fixes: 10c9ead9f3c6 ("rtnetlink: add new RTM_GETSTATS message to dump link stats")
Signed-off-by: Nikolay Aleksandrov <redacted>
---
 net/core/rtnetlink.c | 3 +++
 1 file changed, 3 insertions(+)
diff --git a/net/core/rtnetlink.c b/net/core/rtnetlink.c
index a78fd61da0ec..d4bcdcc68e92 100644
--- a/net/core/rtnetlink.c
+++ b/net/core/rtnetlink.c
@@ -3854,6 +3854,9 @@ static int rtnl_fill_statsinfo(struct sk_buff *skb, struct net_device *dev,
 		return -EMSGSIZE;
 
 	ifsm = nlmsg_data(nlh);
+	ifsm->family = PF_UNSPEC;
+	ifsm->pad1 = 0;
+	ifsm->pad2 = 0;
 	ifsm->ifindex = dev->ifindex;
 	ifsm->filter_mask = filter_mask;
 
-- 
2.1.4

Re: [PATCH net] net: rtnetlink: fix info leak in RTM_GETSTATS call

From: Roopa Prabhu <hidden>
Date: 2017-10-03 14:18:08

On Tue, Oct 3, 2017 at 3:20 AM, Nikolay Aleksandrov
[off-list ref] wrote:
When RTM_GETSTATS was added the fields of its header struct were not all
initialized when returning the result thus leaking 4 bytes of information
to user-space per rtnl_fill_statsinfo call, so initialize them now. Thanks
to Alexander Potapenko for the detailed report and bisection.

Reported-by: Alexander Potapenko <glider@google.com>
Fixes: 10c9ead9f3c6 ("rtnetlink: add new RTM_GETSTATS message to dump link stats")
Signed-off-by: Nikolay Aleksandrov <redacted>
Acked-by: Roopa Prabhu <redacted>

Thanks Nikolay!.

Re: [PATCH net] net: rtnetlink: fix info leak in RTM_GETSTATS call

From: David Miller <davem@davemloft.net>
Date: 2017-10-03 17:19:19

From: Nikolay Aleksandrov <redacted>
Date: Tue,  3 Oct 2017 13:20:48 +0300
When RTM_GETSTATS was added the fields of its header struct were not all
initialized when returning the result thus leaking 4 bytes of information
to user-space per rtnl_fill_statsinfo call, so initialize them now. Thanks
to Alexander Potapenko for the detailed report and bisection.

Reported-by: Alexander Potapenko <glider@google.com>
Fixes: 10c9ead9f3c6 ("rtnetlink: add new RTM_GETSTATS message to dump link stats")
Signed-off-by: Nikolay Aleksandrov <redacted>
Applied and queued up for -stable, thanks.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help