push_rcu() only bounds-checked the traversal stack when
DEBUG is defined. In production the check is compiled out,
leaving an unchecked stack[129] write.
Always check len >= MAX_ALLOWEDIPS_DEPTH and only gate the
WARN splat on DEBUG.
Signed-off-by: quantumvoid0 <redacted>
---
drivers/net/wireguard/allowedips.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/net/wireguard/allowedips.c b/drivers/net/wireguard/allowedips.c
index 5ece9ac..dc383f5 100644
--- a/drivers/net/wireguard/allowedips.c
+++ b/drivers/net/wireguard/allowedips.c
@@ -42,8 +42,10 @@ static void push_rcu(struct allowedips_node **stack,
struct allowedips_node __rcu *p, unsigned int *len)
{
if (rcu_access_pointer(p)) {
- if (WARN_ON(IS_ENABLED(DEBUG) && *len >= MAX_ALLOWEDIPS_DEPTH))
+ if (unlikely(*len >= MAX_ALLOWEDIPS_DEPTH)) {
+ WARN_ON(IS_ENABLED(DEBUG));
return;
+ }
stack[(*len)++] = rcu_dereference_raw(p);
}
}
--2.55.0