Thread (9 messages) flat view 9 messages, 5 authors, 2019-10-04

Re: [Patch net] net_sched: add max len check for TCA_KIND

From: Jakub Kicinski <hidden>
Date: 2019-09-22 02:26:09

On Wed, 18 Sep 2019 22:15:24 -0700, Cong Wang wrote:
On Wed, Sep 18, 2019 at 7:41 PM David Ahern [off-list ref] wrote:
quoted
On 9/18/19 5:24 PM, Cong Wang wrote:  
quoted
The TCA_KIND attribute is of NLA_STRING which does not check
the NUL char. KMSAN reported an uninit-value of TCA_KIND which
is likely caused by the lack of NUL.

Change it to NLA_NUL_STRING and add a max len too.

Fixes: 8b4c3cdd9dd8 ("net: sched: Add policy validation for tc attributes")  
The commit referenced here did not introduce the ability to go beyond
memory boundaries with string comparisons. Rather, it was not complete
solution for attribute validation. I say that wrt to the fix getting
propagated to the correct stable releases.  
I think this patch should be backported to wherever commit 8b4c3cdd9dd8
goes, this is why I picked it as Fixes.
Applied, queued for 4.14+, thanks!
quoted
 
quoted
Reported-and-tested-by: syzbot+618aacd49e8c8b8486bd@syzkaller.appspotmail.com  
What is the actual sysbot report?  
https://marc.info/?l=linux-kernel&m=156862916112881&w=2
  
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help