mirror of
https://github.com/torvalds/linux.git
synced 2026-10-04 02:09:03 +02:00
vsock: ignore empty child namespace mode writes
__vsock_net_mode_string() returns success without updating new_mode when
the transfer length is zero. Its caller then reads the uninitialized enum
and may permanently store a stack-derived value in the write-once child
mode.
Return before calling __vsock_net_mode_string() when *lenp is zero so
that the helper is never invoked with nothing to parse and new_mode is
never read uninitialized. This also prevents an empty write from
locking the current mode.
Fixes: eafb64f40c ("vsock: add netns to vsock core")
Cc: stable@vger.kernel.org
Reviewed-by: Luigi Leonardi <leonardi@redhat.com>
Signed-off-by: Aldo Ariel Panzardo <qwe.aldo@gmail.com>
Reviewed-by: Stefano Garzarella <sgarzare@redhat.com>
Reviewed-by: Bobby Eshleman <bobbyeshleman@meta.com>
Link: https://patch.msgid.link/20260915173050.3176344-1-qwe.aldo@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
This commit is contained in:
parent
b73bcf7c1f
commit
2ec28c09b3
|
|
@ -2889,6 +2889,9 @@ static int vsock_net_child_mode_string(const struct ctl_table *table, int write,
|
|||
|
||||
net = container_of(table->data, struct net, vsock.child_ns_mode);
|
||||
|
||||
if (!*lenp)
|
||||
return 0;
|
||||
|
||||
ret = __vsock_net_mode_string(table, write, buffer, lenp, ppos,
|
||||
vsock_net_child_mode(net), &new_mode);
|
||||
if (ret)
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user