UPSTREAM: bpfilter: reject kernel addresses

The bpfilter user mode helper processes the optval address using
process_vm_readv.  Don't send it kernel addresses fed under
set_fs(KERNEL_DS) as that won't work.

Change-Id: Ifa43c1bea055758b57c5b0a7e46d36036dd09daf
Signed-off-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Tashfin Shakeer Rhythm <tashfinshakeerrhythm@gmail.com>
This commit is contained in:
Christoph Hellwig 2020-07-23 08:08:45 +02:00 • committed by basamaryan
commit 7feeb09195
No known key found for this signature in database
GPG key ID: 210D5384FB2A5885

View file

@ -70,6 +70,10 @@ static int bpfilter_process_sockopt(struct sock *sk, int optname,
.addr = (uintptr_t)optval,
.len = optlen,
};
if (uaccess_kernel()) {
pr_err("kernel access not supported\n");
return -EFAULT;
}
return bpfilter_send_req(&req);
}