Peter Collingbourne
cab0003311
net: don't unconditionally copy_from_user a struct ifreq for socket ioctls
...
commit d0efb16294d145d157432feda83877ae9d7cdf37 upstream.
A common implementation of isatty(3) involves calling a ioctl passing
a dummy struct argument and checking whether the syscall failed --
bionic and glibc use TCGETS (passing a struct termios), and musl uses
TIOCGWINSZ (passing a struct winsize). If the FD is a socket, we will
copy sizeof(struct ifreq) bytes of data from the argument and return
-EFAULT if that fails. The result is that the isatty implementations
may return a non-POSIX-compliant value in errno in the case where part
of the dummy struct argument is inaccessible, as both struct termios
and struct winsize are smaller than struct ifreq (at least on arm64).
Although there is usually enough stack space following the argument
on the stack that this did not present a practical problem up to now,
with MTE stack instrumentation it's more likely for the copy to fail,
as the memory following the struct may have a different tag.
Fix the problem by adding an early check for whether the ioctl is a
valid socket ioctl, and return -ENOTTY if it isn't.
Fixes: 44c02a2c3d ("dev_ioctl(): move copyin/copyout to callers")
Link: https://linux-review.googlesource.com/id/I869da6cf6daabc3e4b7b82ac979683ba05e27d4d
Signed-off-by: Peter Collingbourne <pcc@google.com>
Cc: <stable@vger.kernel.org> # 4.19
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2021-09-03 10:08:16 +02:00
..
6lowpan
9p
802
net/802/garp: fix memleak in garp_request_join()
2021-07-31 08:19:38 +02:00
8021q
net: vlan: avoid leaks on register_vlan_dev() failures
2021-01-17 14:05:31 +01:00
appletalk
appletalk: Fix skb allocation size in loopback case
2021-04-07 14:47:41 +02:00
atm
ax25
batman-adv
batman-adv: Avoid WARN_ON timing related checks
2021-06-23 14:41:23 +02:00
bluetooth
Bluetooth: hidp: use correct wait queue when removing ctrl_wait
2021-08-26 08:36:15 -04:00
bpf
bpfilter
bpfilter: Specify the log level for the kmsg message
2021-07-14 16:53:33 +02:00
bridge
net: bridge: fix memleak in br_add_if()
2021-08-18 08:57:00 +02:00
caif
net: fix uninit-value in caif_seqpkt_sendmsg
2021-07-28 13:30:56 +02:00
can
can: j1939: j1939_session_deactivate(): clarify lifetime of session object
2021-08-04 12:27:40 +02:00
ceph
core
rtnetlink: Return correct error on changing device netns
2021-09-03 10:08:14 +02:00
dcb
net: dcb: Accept RTM_GETDCB messages carrying set-like DCB commands
2021-01-23 15:57:59 +01:00
dccp
dccp: add do-while-0 stubs for dccp_pr_debug macros
2021-08-26 08:36:16 -04:00
decnet
net: decnet: Fix sleeping inside in af_decnet
2021-07-28 13:30:56 +02:00
dns_resolver
dsa
net: dsa: fix error code getting shifted with 4 in dsa_slave_get_sset_count
2021-06-03 08:59:12 +02:00
ethernet
hsr
hsr: use netdev_err() instead of WARN_ONCE()
2021-05-14 09:44:10 +02:00
ieee802154
net: Fix memory leak in ieee802154_raw_deliver
2021-08-18 08:57:00 +02:00
ife
ipv4
ip_gre: add validation for csum_start
2021-09-03 10:08:13 +02:00
ipv6
ipv6: ip6_finish_output2: set sk into newly allocated nskb
2021-07-31 08:19:39 +02:00
iucv
net/af_iucv: remove WARN_ONCE on malformed RX packets
2021-03-07 12:20:42 +01:00
kcm
key
af_key: relax availability checks for skb size calculation
2021-02-13 13:52:54 +01:00
l2tp
l3mdev
lapb
net: lapb: Copy the skb before sending a packet
2021-02-10 09:25:28 +01:00
llc
net: llc: fix skb_over_panic
2021-08-04 12:27:39 +02:00
mac80211
mac80211: remove iwlwifi specific workaround NDPs of null_response
2021-07-14 16:53:32 +02:00
mac802154
net: mac802154: Fix general protection fault
2021-04-14 08:24:18 +02:00
mpls
net: avoid infinite loop in mpls_gso_segment when mpls_hlen == 0
2021-03-17 17:03:31 +01:00
ncsi
net/ncsi: Avoid channel_monitor hrtimer deadlock
2021-04-14 08:24:15 +02:00
netfilter
netfilter: conntrack: collect all entries in one cycle
2021-09-03 10:08:12 +02:00
netlabel
netlabel: Fix memory leak in netlbl_mgmt_add_common
2021-07-14 16:53:29 +02:00
netlink
netlink: disable IRQs for netlink_lock_table()
2021-06-16 11:59:34 +02:00
netrom
netrom: Decrease sock refcount when sock timers expire
2021-07-28 13:30:56 +02:00
nfc
net/nfc/rawsock.c: fix a permission check bug
2021-06-16 11:59:33 +02:00
nsh
openvswitch
ovs: clear skb->tstamp in forwarding path
2021-08-26 08:36:19 -04:00
packet
net/packet: annotate accesses to po->ifindex
2021-06-30 08:47:48 -04:00
phonet
psample
qrtr
net: qrtr: fix another OOB Read in qrtr_endpoint_post
2021-09-03 10:08:12 +02:00
rds
net/rds: dma_map_sg is entitled to merge entries
2021-09-03 10:08:15 +02:00
rfkill
rose
rxrpc
rxrpc: Fix clearance of Tx/Rx ring when releasing a call
2021-02-17 10:35:18 +01:00
sched
net: sched: act_mirred: Reset ct info when mirror/redirect skb
2021-08-18 08:56:59 +02:00
sctp
sctp: move the active_key update after sh_keys is added
2021-08-12 13:20:57 +02:00
smc
Revert "net/smc: fix a NULL pointer dereference"
2021-06-03 08:59:08 +02:00
strparser
sunrpc
SUNRPC: Should wake up the privileged task firstly.
2021-07-14 16:53:05 +02:00
switchdev
net: switchdev: don't set port_obj_info->handled true when -EOPNOTSUPP
2021-02-07 15:35:46 +01:00
tipc
tipc: fix sleeping in tipc accept routine
2021-08-04 12:27:39 +02:00
tls
tls: prevent oversized sendfile() hangs by ignoring MSG_MORE
2021-07-14 16:53:31 +02:00
unix
af_unix: fix garbage collect vs MSG_PEEK
2021-07-31 08:19:37 +02:00
vmw_vsock
vsock/virtio: avoid potential deadlock when vsock device remove
2021-08-18 08:57:01 +02:00
wimax
wireless
cfg80211: Fix possible memory leak in function cfg80211_bss_update
2021-08-04 12:27:38 +02:00
x25
net/x25: Return the correct errno code
2021-06-18 09:59:00 +02:00
xdp
xsk: Simplify detection of empty and full rings
2021-05-22 11:38:27 +02:00
xfrm
xfrm: Fix error reporting in xfrm_state_construct.
2021-07-19 08:53:11 +02:00
compat.c
net: Return the correct errno code
2021-06-18 09:59:00 +02:00
Kconfig
Makefile
socket.c
net: don't unconditionally copy_from_user a struct ifreq for socket ioctls
2021-09-03 10:08:16 +02:00
sysctl_net.c