Eric Dumazet
c77e2ef181
netfilter: nftables: avoid overflows in nft_hash_buckets()
[ Upstream commit a54754ec9891830ba548e2010c889e3c8146e449 ]
Number of buckets being stored in 32bit variables, we have to
ensure that no overflows occur in nft_hash_buckets()
syzbot injected a size == 0x40000000 and reported:
UBSAN: shift-out-of-bounds in ./include/linux/log2.h:57:13
shift exponent 64 is too large for 64-bit type 'long unsigned int'
CPU: 1 PID: 29539 Comm: syz-executor.4 Not tainted 5.12.0-rc7-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Call Trace:
__dump_stack lib/dump_stack.c:79 [inline]
dump_stack+0x141/0x1d7 lib/dump_stack.c:120
ubsan_epilogue+0xb/0x5a lib/ubsan.c:148
__ubsan_handle_shift_out_of_bounds.cold+0xb1/0x181 lib/ubsan.c:327
__roundup_pow_of_two include/linux/log2.h:57 [inline]
nft_hash_buckets net/netfilter/nft_set_hash.c:411 [inline]
nft_hash_estimate.cold+0x19/0x1e net/netfilter/nft_set_hash.c:652
nft_select_set_ops net/netfilter/nf_tables_api.c:3586 [inline]
nf_tables_newset+0xe62/0x3110 net/netfilter/nf_tables_api.c:4322
nfnetlink_rcv_batch+0xa09/0x24b0 net/netfilter/nfnetlink.c:488
nfnetlink_rcv_skb_batch net/netfilter/nfnetlink.c:612 [inline]
nfnetlink_rcv+0x3af/0x420 net/netfilter/nfnetlink.c:630
netlink_unicast_kernel net/netlink/af_netlink.c:1312 [inline]
netlink_unicast+0x533/0x7d0 net/netlink/af_netlink.c:1338
netlink_sendmsg+0x856/0xd90 net/netlink/af_netlink.c:1927
sock_sendmsg_nosec net/socket.c:654 [inline]
sock_sendmsg+0xcf/0x120 net/socket.c:674
____sys_sendmsg+0x6e8/0x810 net/socket.c:2350
___sys_sendmsg+0xf3/0x170 net/socket.c:2404
__sys_sendmsg+0xe5/0x1b0 net/socket.c:2433
do_syscall_64+0x2d/0x70 arch/x86/entry/common.c:46
Fixes: 0ed6389c48 ("netfilter: nf_tables: rename set implementations")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reported-by: syzbot <syzkaller@googlegroups.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
|
2021-05-19 10:08:28 +02:00 |
| .. |
|
6lowpan
|
|
|
|
9p
|
|
|
|
802
|
|
|
|
8021q
|
net: vlan: avoid leaks on register_vlan_dev() failures
|
2021-01-17 14:05:31 +01:00 |
|
appletalk
|
appletalk: Fix skb allocation size in loopback case
|
2021-04-07 14:47:41 +02:00 |
|
atm
|
|
|
|
ax25
|
|
|
|
batman-adv
|
batman-adv: initialize "struct batadv_tvlv_tt_vlan_data"->reserved field
|
2021-04-14 08:24:11 +02:00 |
|
bluetooth
|
Bluetooth: check for zapped sk before connecting
|
2021-05-19 10:08:21 +02:00 |
|
bpf
|
|
|
|
bpfilter
|
|
|
|
bridge
|
net: bridge: when suppression is enabled exclude RARP packets
|
2021-05-19 10:08:21 +02:00 |
|
caif
|
|
|
|
can
|
can: bcm/raw: fix msg_namelen values depending on CAN_REQUIRED_SIZE
|
2021-04-14 08:24:14 +02:00 |
|
ceph
|
libceph: clear con->out_msg on Policy::stateful_server faults
|
2020-11-05 11:43:34 +01:00 |
|
core
|
ethtool: ioctl: Fix out-of-bounds warning in store_link_ksettings_for_user()
|
2021-05-19 10:08:23 +02:00 |
|
dcb
|
net: dcb: Accept RTM_GETDCB messages carrying set-like DCB commands
|
2021-01-23 15:57:59 +01:00 |
|
dccp
|
ipv6: weaken the v4mapped source check
|
2021-04-07 14:47:38 +02:00 |
|
decnet
|
|
|
|
dns_resolver
|
|
|
|
dsa
|
net: dsa: tag_mtk: fix 802.1ad VLAN egress
|
2021-03-20 10:39:47 +01:00 |
|
ethernet
|
|
|
|
hsr
|
hsr: use netdev_err() instead of WARN_ONCE()
|
2021-05-14 09:44:10 +02:00 |
|
ieee802154
|
net: ieee802154: forbid monitor for add llsec seclevel
|
2021-04-21 12:56:15 +02:00 |
|
ife
|
|
|
|
ipv4
|
net: Only allow init netns to set default tcp cong to a restricted algo
|
2021-05-14 09:44:33 +02:00 |
|
ipv6
|
ip6_vti: proper dev_{hold|put} in ndo_[un]init methods
|
2021-05-19 10:08:21 +02:00 |
|
iucv
|
net/af_iucv: remove WARN_ONCE on malformed RX packets
|
2021-03-07 12:20:42 +01:00 |
|
kcm
|
|
|
|
key
|
af_key: relax availability checks for skb size calculation
|
2021-02-13 13:52:54 +01:00 |
|
l2tp
|
|
|
|
l3mdev
|
|
|
|
lapb
|
net: lapb: Copy the skb before sending a packet
|
2021-02-10 09:25:28 +01:00 |
|
llc
|
|
|
|
mac80211
|
mac80211: clear the beacon's CRC after channel switch
|
2021-05-19 10:08:22 +02:00 |
|
mac802154
|
net: mac802154: Fix general protection fault
|
2021-04-14 08:24:18 +02:00 |
|
mpls
|
net: avoid infinite loop in mpls_gso_segment when mpls_hlen == 0
|
2021-03-17 17:03:31 +01:00 |
|
ncsi
|
net/ncsi: Avoid channel_monitor hrtimer deadlock
|
2021-04-14 08:24:15 +02:00 |
|
netfilter
|
netfilter: nftables: avoid overflows in nft_hash_buckets()
|
2021-05-19 10:08:28 +02:00 |
|
netlabel
|
cipso,calipso: resolve a number of problems with the DOI refcounts
|
2021-03-17 17:03:35 +01:00 |
|
netlink
|
|
|
|
netrom
|
|
|
|
nfc
|
net:nfc:digital: Fix a double free in digital_tg_recv_dep_req
|
2021-05-14 09:44:32 +02:00 |
|
nsh
|
|
|
|
openvswitch
|
openvswitch: fix stack OOB read while fragmenting IPv4 packets
|
2021-05-11 14:04:14 +02:00 |
|
packet
|
|
|
|
phonet
|
|
|
|
psample
|
|
|
|
qrtr
|
net: qrtr: fix a kernel-infoleak in qrtr_recvmsg()
|
2021-03-30 14:35:29 +02:00 |
|
rds
|
net/rds: Fix a use after free in rds_message_map_pages
|
2021-04-14 08:24:15 +02:00 |
|
rfkill
|
rfkill: Fix use-after-free in rfkill_resume()
|
2020-11-24 13:29:05 +01:00 |
|
rose
|
rose: Fix Null pointer dereference in rose_send_frame()
|
2020-12-08 10:40:23 +01:00 |
|
rxrpc
|
rxrpc: Fix clearance of Tx/Rx ring when releasing a call
|
2021-02-17 10:35:18 +01:00 |
|
sched
|
net: sched: tapr: prevent cycle_time == 0 in parse_taprio_schedule
|
2021-05-19 10:08:23 +02:00 |
|
sctp
|
sctp: fix a SCTP_MIB_CURRESTAB leak in sctp_sf_do_dupcook_b
|
2021-05-19 10:08:27 +02:00 |
|
smc
|
smc: disallow TCP_ULP in smc_setsockopt()
|
2021-05-19 10:08:28 +02:00 |
|
strparser
|
|
|
|
sunrpc
|
sunrpc: Fix misplaced barrier in call_decode
|
2021-05-19 10:08:27 +02:00 |
|
switchdev
|
net: switchdev: don't set port_obj_info->handled true when -EOPNOTSUPP
|
2021-02-07 15:35:46 +01:00 |
|
tipc
|
tipc: convert dest node's address to network order
|
2021-05-19 10:08:20 +02:00 |
|
tls
|
net/tls: Protect from calling tls_dev_del for TLS RX twice
|
2020-12-08 10:40:23 +01:00 |
|
unix
|
|
|
|
vmw_vsock
|
vsock/vmci: log once the failed queue pair allocation
|
2021-05-14 09:44:30 +02:00 |
|
wimax
|
|
|
|
wireless
|
cfg80211: scan: drop entry from hidden_list on overflow
|
2021-05-14 09:44:13 +02:00 |
|
x25
|
net/x25: prevent a couple of overflows
|
2020-12-08 10:40:26 +01:00 |
|
xdp
|
xsk: Replace datagram_poll by sock_poll_wait
|
2020-12-30 11:50:53 +01:00 |
|
xfrm
|
net: xfrm: Localize sequence counter per network namespace
|
2021-04-14 08:24:13 +02:00 |
|
compat.c
|
|
|
|
Kconfig
|
|
|
|
Makefile
|
|
|
|
socket.c
|
|
|
|
sysctl_net.c
|
|
|