Thread (11 messages) flat view 11 messages, 4 authors, 2021-06-10

Re: [PATCH net 3/3] sch_cake: Fix out of bounds when parsing TCP options

From: Toke Høiland-Jørgensen <toke@toke.dk>
Date: 2021-06-09 22:00:51

Maxim Mikityanskiy [off-list ref] writes:
The TCP option parser in cake qdisc (cake_get_tcpopt and
cake_tcph_may_drop) could read one byte out of bounds. When the length
is 1, the execution flow gets into the loop, reads one byte of the
opcode, and if the opcode is neither TCPOPT_EOL nor TCPOPT_NOP, it reads
one more byte, which exceeds the length of 1.

This fix is inspired by commit 9609dad263f8 ("ipv4: tcp_input: fix stack
out of bounds when parsing TCP options.").

Cc: Young Xiao <redacted>
Fixes: 8b7138814f29 ("sch_cake: Add optional ACK filter")
Signed-off-by: Maxim Mikityanskiy <redacted>
Thanks for fixing this!

Acked-by: Toke Høiland-Jørgensen <toke@toke.dk>
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help