Szymon Heidrich
ebe6d2fcf7
usb: rndis_host: Secure rndis_query check against int overflow
...
[ Upstream commit c7dd13805f8b8fc1ce3b6d40f6aff47e66b72ad2 ]
Variables off and len typed as uint32 in rndis_query function
are controlled by incoming RNDIS response message thus their
value may be manipulated. Setting off to a unexpectetly large
value will cause the sum with len and 8 to overflow and pass
the implemented validation step. Consequently the response
pointer will be referring to a location past the expected
buffer boundaries allowing information leakage e.g. via
RNDIS_OID_802_3_PERMANENT_ADDRESS OID.
Fixes: ddda086240 ("USB: rndis_host, various cleanups")
Signed-off-by: Szymon Heidrich <szymon.heidrich@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2023-01-18 11:41:58 +01:00
..
appletalk
arcnet
bonding
drivers/net/bonding/bond_3ad: return when there's no aggregator
2023-01-18 11:41:58 +01:00
caif
can
can: tcan4x5x: Remove invalid write in clear_interrupts
2023-01-18 11:41:15 +01:00
dsa
net: lan9303: Fix read error execution path
2023-01-18 11:41:15 +01:00
ethernet
net: amd-xgbe: add missed tasklet_kill
2023-01-18 11:41:57 +01:00
fddi
net: defxx: Fix missing err handling in dfx_init()
2023-01-18 11:41:13 +01:00
fjes
hamradio
hamradio: baycom_epp: Fix return type of baycom_send_packet()
2023-01-18 11:41:35 +01:00
hippi
hyperv
hv_netvsc: Fix race between VF offering and VF association message from host
2022-10-29 10:20:36 +02:00
ieee802154
ca8210: Fix crash by zero initializing data
2022-12-14 11:30:44 +01:00
ipvlan
ipvlan: Fix out-of-bound bugs caused by unset skb->mac_header
2022-09-28 11:04:05 +02:00
netdevsim
netdevsim: Avoid allocation warnings triggered from user space
2022-08-25 11:17:49 +02:00
phy
net: phy: xgmiitorgmii: Fix refcount leak in xgmiitorgmii_probe
2023-01-18 11:41:57 +01:00
plip
net: plip: don't call kfree_skb/dev_kfree_skb() under spin_lock_irq()
2022-12-14 11:30:48 +01:00
ppp
ppp: associate skb with a device at tx
2023-01-18 11:41:37 +01:00
slip
team
net: team: Unsync device addresses on ndo_stop
2022-09-28 11:04:05 +02:00
usb
usb: rndis_host: Secure rndis_query check against int overflow
2023-01-18 11:41:58 +01:00
vmxnet3
wan
net: farsync: Fix kmemleak when rmmods farsync
2023-01-18 11:41:14 +01:00
wimax
wireless
wifi: brcmfmac: Fix potential shift-out-of-bounds in brcmf_fw_alloc_request()
2023-01-18 11:41:36 +01:00
xen-netback
xen-netback: move removal of "hotplug-status" to the right place
2023-01-18 11:40:48 +01:00
dummy.c
eql.c
geneve.c
geneve: do not use RT_TOS for IPv6 flowlabel
2022-08-25 11:18:24 +02:00
gtp.c
ifb.c
Kconfig
LICENSE.SRC
loopback.c
net: loopback: use NET_NAME_PREDICTABLE for name_assign_type
2023-01-18 11:40:49 +01:00
macsec.c
macvlan.c
macvlan: enforce a consistent minimal mtu
2022-11-25 17:42:21 +01:00
macvtap.c
Makefile
mdio.c
mii.c
net_failover.c
netconsole.c
nlmon.c
ntb_netdev.c
ntb_netdev: Use dev_kfree_skb_any() in interrupt context
2023-01-18 11:41:16 +01:00
rionet.c
sb1000.c
Space.c
sungem_phy.c
net: sungem_phy: Add of_node_put() for reference returned by of_get_parent()
2022-08-03 11:59:39 +02:00
tap.c
thunderbolt.c
net: thunderbolt: Fix error handling in tbnet_init()
2022-11-25 17:42:16 +01:00
tun.c
net: tun: Fix use-after-free in tun_detach()
2022-12-08 11:23:03 +01:00
veth.c
virtio_net.c
virtio-net: fix the race between refill work and close
2022-08-03 11:59:41 +02:00
vrf.c
vsockmon.c
vxlan.c
xen-netfront.c
xen-netfront: Fix NULL sring after live migration
2022-12-14 11:30:45 +01:00