Herbert Xu
cc0f678353
crypto: af_alg - fix use-after-free in af_alg_accept() due to bh_lock_sock()
...
commit 34c86f4c4a7be3b3e35aa48bd18299d4c756064d upstream.
The locking in af_alg_release_parent is broken as the BH socket
lock can only be taken if there is a code-path to handle the case
where the lock is owned by process-context. Instead of adding
such handling, we can fix this by changing the ref counts to
atomic_t.
This patch also modifies the main refcnt to include both normal
and nokey sockets. This way we don't have to fudge the nokey
ref count when a socket changes from nokey to normal.
Credits go to Mauricio Faria de Oliveira who diagnosed this bug
and sent a patch for it:
https://lore.kernel.org/linux-crypto/20200605161657.535043-1-mfo@canonical.com/
Reported-by: Brian Moyles <bmoyles@netflix.com>
Reported-by: Mauricio Faria de Oliveira <mfo@canonical.com>
Fixes: 37f96694cf73 ("crypto: af_alg - Use bh_lock_sock in...")
Cc: <stable@vger.kernel.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2020-07-09 09:37:52 +02:00
..
internal
crypto: algif_skcipher - Use chunksize instead of blocksize
2020-01-17 19:48:46 +01:00
acompress.h
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 152
2019-05-30 11:26:32 -07:00
aead.h
Merge branch 'linus' of git://git.kernel.org/pub/scm/linux/kernel/git/herbert/crypto-2.6
2019-07-08 20:57:08 -07:00
aes.h
crypto: aes - helper function to validate key length for AES algorithms
2019-08-09 15:11:43 +10:00
akcipher.h
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 152
2019-05-30 11:26:32 -07:00
algapi.h
crypto: api - Remove redundant #ifdef in crypto_yield()
2019-08-02 14:45:13 +10:00
arc4.h
crypto: arc4 - refactor arc4 core code into separate library
2019-06-20 14:18:33 +08:00
asym_tpm_subtype.h
authenc.h
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 152
2019-05-30 11:26:32 -07:00
b128ops.h
blowfish.h
cast5.h
cast6.h
cast_common.h
cbc.h
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 152
2019-05-30 11:26:32 -07:00
chacha.h
crypto: chacha - constify ctx and iv arguments
2019-06-13 14:31:40 +08:00
cryptd.h
ctr.h
crypto: ctr - add helper for performing a CTR encryption walk
2019-07-26 14:56:07 +10:00
des.h
crypto: des - remove now unused __des3_ede_setkey()
2019-08-22 14:57:33 +10:00
dh.h
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 152
2019-05-30 11:26:32 -07:00
drbg.h
ecdh.h
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 152
2019-05-30 11:26:32 -07:00
engine.h
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 152
2019-05-30 11:26:32 -07:00
gcm.h
crypto: gcm - helper functions for assoclen/authsize check
2019-08-09 15:11:41 +10:00
gf128mul.h
ghash.h
crypto: ghash - add comment and improve help text
2019-07-27 21:08:38 +10:00
hash.h
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 152
2019-05-30 11:26:32 -07:00
hash_info.h
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 152
2019-05-30 11:26:32 -07:00
hmac.h
if_alg.h
crypto: af_alg - fix use-after-free in af_alg_accept() due to bh_lock_sock()
2020-07-09 09:37:52 +02:00
kpp.h
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 152
2019-05-30 11:26:32 -07:00
md5.h
nhpoly1305.h
null.h
padlock.h
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 152
2019-05-30 11:26:32 -07:00
pcrypt.h
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 335
2019-06-05 17:37:06 +02:00
pkcs7.h
PKCS#7: Introduce pkcs7_get_digest()
2019-08-05 18:40:19 -04:00
poly1305.h
public_key.h
rng.h
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 152
2019-05-30 11:26:32 -07:00
scatterwalk.h
treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 152
2019-05-30 11:26:32 -07:00
serpent.h
sha.h
crypto: sha256 - Remove sha256/224_init code duplication
2019-09-05 14:54:54 +10:00
sha1_base.h
crypto: add header include guards
2019-08-02 14:44:02 +10:00
sha3.h
sha256_base.h
crypto: sha256 - Remove sha256/224_init code duplication
2019-09-05 14:54:54 +10:00
sha512_base.h
crypto: add header include guards
2019-08-02 14:44:02 +10:00
skcipher.h
crypto: algif_skcipher - Use chunksize instead of blocksize
2020-01-17 19:48:46 +01:00
sm3.h
sm3_base.h
crypto: add header include guards
2019-08-02 14:44:02 +10:00
sm4.h
streebog.h
twofish.h
xts.h