[PATCH V2] fix array-index-out-of-bounds in taprio_change

Subsystems: cbs/etf/taprio qdiscs, networking [general], tc subsystem, the rest

STALE1809d

4 messages, 4 authors, 2021-08-31 · open the first message on its own page

[PATCH V2] fix array-index-out-of-bounds in taprio_change

From: <hidden>
Date: 2021-08-30 03:47:34

From: Haimin Zhang <redacted>

syzbot report an array-index-out-of-bounds in taprio_change
index 16 is out of range for type '__u16 [16]'
that's because mqprio->num_tc is lager than TC_MAX_QUEUE,so we check
the return value of netdev_set_num_tc.

Reported-by: syzbot+2b3e5fb6c7ef285a94f6@syzkaller.appspotmail.com
Signed-off-by: Haimin Zhang <redacted>
---
 net/sched/sch_taprio.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/net/sched/sch_taprio.c b/net/sched/sch_taprio.c
index 9c79374..1ab2fc9 100644
--- a/net/sched/sch_taprio.c
+++ b/net/sched/sch_taprio.c
@@ -1513,7 +1513,9 @@ static int taprio_change(struct Qdisc *sch, struct nlattr *opt,
 	taprio_set_picos_per_byte(dev, q);
 
 	if (mqprio) {
-		netdev_set_num_tc(dev, mqprio->num_tc);
+		err = netdev_set_num_tc(dev, mqprio->num_tc);
+		if (err)
+			goto free_sched;
 		for (i = 0; i < mqprio->num_tc; i++)
 			netdev_set_tc_queue(dev, i,
 					    mqprio->count[i],
-- 
1.8.3.1

Re: [PATCH V2] fix array-index-out-of-bounds in taprio_change

From: patchwork-bot+netdevbpf@kernel.org
Date: 2021-08-30 11:30:13

Hello:

This patch was applied to netdev/net-next.git (refs/heads/master):

On Mon, 30 Aug 2021 11:47:01 +0800 you wrote:
From: Haimin Zhang <redacted>

syzbot report an array-index-out-of-bounds in taprio_change
index 16 is out of range for type '__u16 [16]'
that's because mqprio->num_tc is lager than TC_MAX_QUEUE,so we check
the return value of netdev_set_num_tc.

[...]
Here is the summary with links:
  - [V2] fix array-index-out-of-bounds in taprio_change
    https://git.kernel.org/netdev/net-next/c/efe487fce306

You are awesome, thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html

Re: [PATCH V2] fix array-index-out-of-bounds in taprio_change

From: Jakub Kicinski <kuba@kernel.org>
Date: 2021-08-30 17:15:01

On Mon, 30 Aug 2021 11:30:06 +0000 patchwork-bot+netdevbpf@kernel.org
wrote:
Hello:

This patch was applied to netdev/net-next.git (refs/heads/master):

On Mon, 30 Aug 2021 11:47:01 +0800 you wrote:
quoted
From: Haimin Zhang <redacted>

syzbot report an array-index-out-of-bounds in taprio_change
index 16 is out of range for type '__u16 [16]'
that's because mqprio->num_tc is lager than TC_MAX_QUEUE,so we check
the return value of netdev_set_num_tc.

[...]  
Here is the summary with links:
  - [V2] fix array-index-out-of-bounds in taprio_change
    https://git.kernel.org/netdev/net-next/c/efe487fce306

You are awesome, thank you!
https://lore.kernel.org/netdev/20210830091046.610ceb1b@kicinski-fedora-pc1c0hjn.dhcp.thefacebook.com/

Oh, well...

Re: [PATCH V2] fix array-index-out-of-bounds in taprio_change

From: Cong Wang <hidden>
Date: 2021-08-31 05:56:37

On Mon, Aug 30, 2021 at 10:14 AM Jakub Kicinski [off-list ref] wrote:
On Mon, 30 Aug 2021 11:30:06 +0000 patchwork-bot+netdevbpf@kernel.org
wrote:
quoted
Hello:

This patch was applied to netdev/net-next.git (refs/heads/master):

On Mon, 30 Aug 2021 11:47:01 +0800 you wrote:
quoted
From: Haimin Zhang <redacted>

syzbot report an array-index-out-of-bounds in taprio_change
index 16 is out of range for type '__u16 [16]'
that's because mqprio->num_tc is lager than TC_MAX_QUEUE,so we check
the return value of netdev_set_num_tc.

[...]
Here is the summary with links:
  - [V2] fix array-index-out-of-bounds in taprio_change
    https://git.kernel.org/netdev/net-next/c/efe487fce306

You are awesome, thank you!
https://lore.kernel.org/netdev/20210830091046.610ceb1b@kicinski-fedora-pc1c0hjn.dhcp.thefacebook.com/

Oh, well...
I agree it is slightly better to make the check work in
taprio_parse_mqprio_opt(), but this patch is not bad either, we
need to check the return value of netdev_set_num_tc() for
completeness at least.

BTW, this patch should be landed in -net, not -net-next, as it
fixes a real bug reported by syzbot.

Thanks.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help