]> git.baikalelectronics.ru Git - kernel.git/commit
ipv6: fix out of bound writes in __ip6_append_data()
authorEric Dumazet <edumazet@google.com>
Fri, 19 May 2017 21:17:48 +0000 (14:17 -0700)
committerDavid S. Miller <davem@davemloft.net>
Mon, 22 May 2017 15:47:44 +0000 (11:47 -0400)
commit8026d5073caa59a81b6d53aecc0a1b9f85fa7d76
treec4c562db86e7f3c60775748ce696efc2a0b8b54b
parent67b8632cfbad84e74e6bd1db8ed398166a1b222d
ipv6: fix out of bound writes in __ip6_append_data()

Andrey Konovalov and idaifish@gmail.com reported crashes caused by
one skb shared_info being overwritten from __ip6_append_data()

Andrey program lead to following state :

copy -4200 datalen 2000 fraglen 2040
maxfraglen 2040 alloclen 2048 transhdrlen 0 offset 0 fraggap 6200

The skb_copy_and_csum_bits(skb_prev, maxfraglen, data + transhdrlen,
fraggap, 0); is overwriting skb->head and skb_shared_info

Since we apparently detect this rare condition too late, move the
code earlier to even avoid allocating skb and risking crashes.

Once again, many thanks to Andrey and syzkaller team.

Signed-off-by: Eric Dumazet <edumazet@google.com>
Reported-by: Andrey Konovalov <andreyknvl@google.com>
Tested-by: Andrey Konovalov <andreyknvl@google.com>
Reported-by: <idaifish@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
net/ipv6/ip6_output.c