mirror of
https://github.com/torvalds/linux.git
synced 2026-07-27 09:36:22 +02:00
batman-adv: tt: prevent TVLV OOB check overflow
A TT unicast TVLV contains the number of VLANs stored in it. This number is
an u16 and gets multiplied by the size of the struct
batadv_tvlv_tt_vlan_data (8 bytes). The size can therefore overflow the u16
used to store the tt_vlan_len. All additional safety checks to prevent
out-of-bounds access of the TVLV buffer are invalid due to this overflow.
Using size_t prevents this overflow and ensures that the safety checks
compare against the actual buffer requirements.
Cc: stable@vger.kernel.org
Fixes: 7ea7b4a142 ("batman-adv: make the TT CRC logic VLAN specific")
Signed-off-by: Sven Eckelmann <sven@narfation.org>
This commit is contained in:
parent
27c7d40008
commit
7a581d9aab
|
|
@ -4033,7 +4033,8 @@ static int batadv_tt_tvlv_unicast_handler_v1(struct batadv_priv *bat_priv,
|
|||
u16 tvlv_value_len)
|
||||
{
|
||||
struct batadv_tvlv_tt_data *tt_data;
|
||||
u16 tt_vlan_len, tt_num_entries;
|
||||
u16 tt_num_entries;
|
||||
size_t tt_vlan_len;
|
||||
char tt_flag;
|
||||
bool ret;
|
||||
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user