Thread (2 messages) 2 messages, 2 authors, 2023-08-30

Re: [PATCH nf] netfilter/osf: avoid OOB read

From: Florian Westphal <fw@strlen.de>
Date: 2023-08-30 23:00:00
Also in: lkml, netfilter-devel

Wander Lairson Costa [off-list ref] wrote:
The opt_num field is controlled by user mode and is not currently
validated inside the kernel. An attacker can take advantage of this to
trigger an OOB read and potentially leak information.
[..]

Can you send a v2 that rejects bogus nf_osf_user_finger structs?

nfnl_osf_add_callback() seems to be the right place to refuse it.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help