]> git.baikalelectronics.ru Git - kernel.git/commit
mptcp: Fix out of bounds when parsing TCP options
authorMaxim Mikityanskiy <maximmi@nvidia.com>
Thu, 10 Jun 2021 16:40:30 +0000 (19:40 +0300)
committerDavid S. Miller <davem@davemloft.net>
Thu, 10 Jun 2021 21:26:18 +0000 (14:26 -0700)
commit412096b75ab81224fa896e74179dc74b2cba6e28
treed708cf35e5b0becfc985b668ae5edc357dd66700
parent59eeadd3c0452328aba3fa22434e2492b83793b5
mptcp: Fix out of bounds when parsing TCP options

The TCP option parser in mptcp (mptcp_get_options) could read one byte
out of bounds. When the length is 1, the execution flow gets into the
loop, reads one byte of the opcode, and if the opcode is neither
TCPOPT_EOL nor TCPOPT_NOP, it reads one more byte, which exceeds the
length of 1.

This fix is inspired by commit fae93b8ae922 ("ipv4: tcp_input: fix stack
out of bounds when parsing TCP options.").

Cc: Young Xiao <92siuyang@gmail.com>
Fixes: 67d38781cb8e ("mptcp: Handle MP_CAPABLE options for outgoing connections")
Signed-off-by: Maxim Mikityanskiy <maximmi@nvidia.com>
Reviewed-by: Mat Martineau <mathew.j.martineau@linux.intel.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
net/mptcp/options.c