Thread (1 message) 1 message, 1 author, 2018-08-27

Re: [PATCH] net: sched: Fix memory exposure from short TCA_U32_SEL

From: Roman Mashak <hidden>
Date: 2018-08-27 14:26:08
Also in: lkml

Kees Cook [off-list ref] writes:
On Mon, Aug 27, 2018 at 4:46 AM, Jamal Hadi Salim [off-list ref] wrote:
quoted
On 2018-08-26 5:56 p.m., Kees Cook wrote:
quoted
On Sun, Aug 26, 2018 at 10:30 AM, Jamal Hadi Salim [off-list ref]
wrote:
quoted
We should add an nla_policy later.

What's the right way to do that for cases like this?

Meant something like attached which you alluded-to in your comments
would give an upper bound (Max allowed keys is 128).
The problem is that policy doesn't parse the contents: "nkeys"
determines the size, so we have to both validate minimum size (to be
sure the location of "nkeys" is valid) and check that the size is at
least nkeys * struct long. I don't think there is a way to do this
with the existing policy language.
While at these changes, could you also add and export in UAPI max
allowed keys count, which is currently 128? For example,
TCA_U32_NKEYS_MAX in pkt_cls.h
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help