mirror of
https://github.com/torvalds/linux.git
synced 2026-07-28 01:55:51 +02:00
net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post()
qrtr_endpoint_post() validates an incoming packet with if (!size || len != ALIGN(size, 4) + hdrlen) goto err; where size comes from the wire. On 32-bit, size_t is 32 bits and ALIGN(size, 4) wraps to 0 for size >= 0xfffffffd, so the check passes and skb_put_data(skb, data + hdrlen, size) writes past the hdrlen-sized skb and oopses the kernel. 64-bit is unaffected. This is the 32-bit residual ofad9d24c942("net: qrtr: fix OOB Read in qrtr_endpoint_post"), which fixed only the 64-bit case. Reject any size that cannot fit the buffer before the ALIGN. Fixes:ad9d24c942("net: qrtr: fix OOB Read in qrtr_endpoint_post") Cc: stable@vger.kernel.org Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com> Reviewed-by: Simon Horman <horms@kernel.org> Link: https://patch.msgid.link/20260611125455.2352279-1-michael.bommarito@gmail.com Signed-off-by: Jakub Kicinski <kuba@kernel.org>
This commit is contained in:
parent
d7b0413b35
commit
2005486977
|
|
@ -496,7 +496,7 @@ int qrtr_endpoint_post(struct qrtr_endpoint *ep, const void *data, size_t len)
|
|||
if (cb->dst_port == QRTR_PORT_CTRL_LEGACY)
|
||||
cb->dst_port = QRTR_PORT_CTRL;
|
||||
|
||||
if (!size || len != ALIGN(size, 4) + hdrlen)
|
||||
if (!size || size > len || len != ALIGN(size, 4) + hdrlen)
|
||||
goto err;
|
||||
|
||||
if ((cb->type == QRTR_TYPE_NEW_SERVER ||
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user