Ilya Shchipletsov
64e9f54a14
netrom: check buffer length before accessing it
[ Upstream commit a4fd163aed2edd967a244499754dec991d8b4c7d ]
Syzkaller reports an uninit value read from ax25cmp when sending raw message
through ieee802154 implementation.
=====================================================
BUG: KMSAN: uninit-value in ax25cmp+0x3a5/0x460 net/ax25/ax25_addr.c:119
ax25cmp+0x3a5/0x460 net/ax25/ax25_addr.c:119
nr_dev_get+0x20e/0x450 net/netrom/nr_route.c:601
nr_route_frame+0x1a2/0xfc0 net/netrom/nr_route.c:774
nr_xmit+0x5a/0x1c0 net/netrom/nr_dev.c:144
__netdev_start_xmit include/linux/netdevice.h:4940 [inline]
netdev_start_xmit include/linux/netdevice.h:4954 [inline]
xmit_one net/core/dev.c:3548 [inline]
dev_hard_start_xmit+0x247/0xa10 net/core/dev.c:3564
__dev_queue_xmit+0x33b8/0x5130 net/core/dev.c:4349
dev_queue_xmit include/linux/netdevice.h:3134 [inline]
raw_sendmsg+0x654/0xc10 net/ieee802154/socket.c:299
ieee802154_sock_sendmsg+0x91/0xc0 net/ieee802154/socket.c:96
sock_sendmsg_nosec net/socket.c:730 [inline]
__sock_sendmsg net/socket.c:745 [inline]
____sys_sendmsg+0x9c2/0xd60 net/socket.c:2584
___sys_sendmsg+0x28d/0x3c0 net/socket.c:2638
__sys_sendmsg net/socket.c:2667 [inline]
__do_sys_sendmsg net/socket.c:2676 [inline]
__se_sys_sendmsg net/socket.c:2674 [inline]
__x64_sys_sendmsg+0x307/0x490 net/socket.c:2674
do_syscall_x64 arch/x86/entry/common.c:52 [inline]
do_syscall_64+0x44/0x110 arch/x86/entry/common.c:83
entry_SYSCALL_64_after_hwframe+0x63/0x6b
Uninit was created at:
slab_post_alloc_hook+0x129/0xa70 mm/slab.h:768
slab_alloc_node mm/slub.c:3478 [inline]
kmem_cache_alloc_node+0x5e9/0xb10 mm/slub.c:3523
kmalloc_reserve+0x13d/0x4a0 net/core/skbuff.c:560
__alloc_skb+0x318/0x740 net/core/skbuff.c:651
alloc_skb include/linux/skbuff.h:1286 [inline]
alloc_skb_with_frags+0xc8/0xbd0 net/core/skbuff.c:6334
sock_alloc_send_pskb+0xa80/0xbf0 net/core/sock.c:2780
sock_alloc_send_skb include/net/sock.h:1884 [inline]
raw_sendmsg+0x36d/0xc10 net/ieee802154/socket.c:282
ieee802154_sock_sendmsg+0x91/0xc0 net/ieee802154/socket.c:96
sock_sendmsg_nosec net/socket.c:730 [inline]
__sock_sendmsg net/socket.c:745 [inline]
____sys_sendmsg+0x9c2/0xd60 net/socket.c:2584
___sys_sendmsg+0x28d/0x3c0 net/socket.c:2638
__sys_sendmsg net/socket.c:2667 [inline]
__do_sys_sendmsg net/socket.c:2676 [inline]
__se_sys_sendmsg net/socket.c:2674 [inline]
__x64_sys_sendmsg+0x307/0x490 net/socket.c:2674
do_syscall_x64 arch/x86/entry/common.c:52 [inline]
do_syscall_64+0x44/0x110 arch/x86/entry/common.c:83
entry_SYSCALL_64_after_hwframe+0x63/0x6b
CPU: 0 PID: 5037 Comm: syz-executor166 Not tainted 6.7.0-rc7-syzkaller-00003-gfbafc3e621c3 #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 11/17/2023
=====================================================
This issue occurs because the skb buffer is too small, and it's actual
allocation is aligned. This hides an actual issue, which is that nr_route_frame
does not validate the buffer size before using it.
Fix this issue by checking skb->len before accessing any fields in skb->data.
Found by Linux Verification Center (linuxtesting.org) with Syzkaller.
Fixes: 1da177e4c3 ("Linux-2.6.12-rc2")
Co-developed-by: Nikita Marushkin <hfggklm@gmail.com>
Signed-off-by: Nikita Marushkin <hfggklm@gmail.com>
Signed-off-by: Ilya Shchipletsov <rabbelkin@mail.ru>
Link: https://patch.msgid.link/20241219082308.3942-1-rabbelkin@mail.ru
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
|
2025-01-09 13:23:35 +01:00 |
| .. |
|
6lowpan
|
|
|
|
9p
|
9p/xen: fix release of IRQ
|
2024-12-14 19:44:41 +01:00 |
|
802
|
|
|
|
8021q
|
vlan: skip nested type that is not IFLA_VLAN_QOS_MAPPING
|
2024-02-23 08:24:50 +01:00 |
|
appletalk
|
|
|
|
atm
|
|
|
|
ax25
|
|
|
|
batman-adv
|
batman-adv: Do not let TT changes list grows indefinitely
|
2024-12-19 18:05:03 +01:00 |
|
bluetooth
|
Bluetooth: L2CAP: do not leave dangling sk pointer on error in l2cap_sock_create()
|
2024-12-14 19:44:51 +01:00 |
|
bpf
|
|
|
|
bpfilter
|
|
|
|
bridge
|
net: bridge: xmit: make sure we have at least eth header len bytes
|
2024-11-17 14:58:51 +01:00 |
|
caif
|
|
|
|
can
|
net: af_can: do not leave a dangling sk pointer in can_create()
|
2024-12-14 19:44:51 +01:00 |
|
ceph
|
libceph: fix race between delayed_work() and ceph_monc_stop()
|
2024-07-18 11:40:55 +02:00 |
|
core
|
skb_expand_head() adjust skb->truesize incorrectly
|
2025-01-09 13:23:33 +01:00 |
|
dcb
|
|
|
|
dccp
|
dccp: Fix memory leak in dccp_feat_change_recv
|
2024-12-14 19:44:45 +01:00 |
|
decnet
|
|
|
|
dns_resolver
|
|
|
|
dsa
|
|
|
|
ethernet
|
ethernet: Add helper for assigning packet type when dest address does not match device address
|
2024-05-02 16:18:36 +02:00 |
|
hsr
|
hsr: Handle failures in module init
|
2024-03-26 18:22:25 -04:00 |
|
ieee802154
|
net: ieee802154: do not leave a dangling sk pointer in ieee802154_create()
|
2024-12-14 19:44:51 +01:00 |
|
ife
|
|
|
|
ipv4
|
net: inet: do not leave a dangling sk pointer in inet_create()
|
2024-12-14 19:44:51 +01:00 |
|
ipv6
|
ipv6: prevent possible UAF in ip6_xmit()
|
2025-01-09 13:23:33 +01:00 |
|
iucv
|
s390/iucv: fix receive buffer virtual vs physical address confusion
|
2024-09-04 13:14:57 +02:00 |
|
kcm
|
kcm: Serialise kcm_sendmsg() for the same socket.
|
2024-09-04 13:14:59 +02:00 |
|
key
|
|
|
|
l2tp
|
genetlink: hold RCU in genlmsg_mcast()
|
2024-11-08 16:20:50 +01:00 |
|
l3mdev
|
|
|
|
lapb
|
|
|
|
llc
|
llc: call sock_orphan() at release time
|
2024-02-23 08:25:04 +01:00 |
|
mac80211
|
mac80211: fix user-power when emulating chanctx
|
2024-12-14 19:44:20 +01:00 |
|
mac802154
|
net: mac802154: Fix racy device stats updates by DEV_STATS_INC() and DEV_STATS_ADD()
|
2024-07-27 10:38:31 +02:00 |
|
mpls
|
|
|
|
ncsi
|
net/ncsi: Fix netlink major/minor version numbers
|
2024-01-25 14:34:25 -08:00 |
|
netfilter
|
netfilter: ipset: Fix for recursive locking warning
|
2025-01-09 13:23:28 +01:00 |
|
netlabel
|
calipso: fix memory leak in netlbl_calipso_add_pass()
|
2024-01-25 14:34:23 -08:00 |
|
netlink
|
netlink: terminate outstanding dump on socket close
|
2024-12-14 19:44:18 +01:00 |
|
netrom
|
netrom: check buffer length before accessing it
|
2025-01-09 13:23:35 +01:00 |
|
nfc
|
nfc: nci: Fix handling of zero-length payload packets in nci_rx_work()
|
2024-06-16 13:28:46 +02:00 |
|
nsh
|
nsh: Restore skb->{protocol,data,mac_header} for outer header in nsh_gso_segment().
|
2024-05-17 11:43:49 +02:00 |
|
openvswitch
|
openvswitch: Set the skbuff pkt_type for proper pmtud support.
|
2024-06-16 13:28:45 +02:00 |
|
packet
|
af_packet: avoid erroring out after sock_init_data() in packet_create()
|
2024-12-14 19:44:51 +01:00 |
|
phonet
|
phonet: fix rtm_phonet_notify() skb allocation
|
2024-05-17 11:43:54 +02:00 |
|
psample
|
|
|
|
qrtr
|
net: qrtr: Update packets cloning when broadcasting
|
2024-11-08 16:20:33 +01:00 |
|
rds
|
net:rds: Fix possible deadlock in rds_message_put
|
2024-09-04 13:15:03 +02:00 |
|
rfkill
|
net: rfkill: gpio: Add check for clk_enable()
|
2024-12-14 19:44:27 +01:00 |
|
rose
|
net/rose: fix races in rose_kill_by_device()
|
2024-01-08 11:29:44 +01:00 |
|
rxrpc
|
rxrpc: Fix response to PING RESPONSE ACKs to a dead call
|
2024-02-23 08:25:07 +01:00 |
|
sched
|
net: sched: fix ordering of qlen adjustment
|
2025-01-09 13:23:26 +01:00 |
|
sctp
|
sctp: properly validate chunk size in sctp_sf_ootb()
|
2024-11-17 14:58:50 +01:00 |
|
smc
|
net/smc: check sndbuf_space again after NOSPACE flag is set in smc_poll
|
2025-01-09 13:23:27 +01:00 |
|
strparser
|
|
|
|
sunrpc
|
sunrpc: clear XPRT_SOCK_UPD_TIMEOUT when reset transport
|
2024-12-14 19:44:42 +01:00 |
|
switchdev
|
|
|
|
tipc
|
tipc: fix NULL deref in cleanup_bearer()
|
2024-12-19 18:05:03 +01:00 |
|
tls
|
tls: stop recv() if initial process_rx_list gave us non-DATA
|
2024-03-01 13:13:37 +01:00 |
|
unix
|
af_unix: Remove put_pid()/put_cred() in copy_peercred().
|
2024-09-12 11:03:52 +02:00 |
|
vmw_vsock
|
vsock/virtio: Initialization of the dangling pointer occurring in vsk->trans
|
2024-11-17 14:58:52 +01:00 |
|
wimax
|
|
|
|
wireless
|
genetlink: hold RCU in genlmsg_mcast()
|
2024-11-08 16:20:50 +01:00 |
|
x25
|
net/x25: fix incorrect parameter validation in the x25_getsockopt() function
|
2024-03-26 18:22:18 -04:00 |
|
xdp
|
xsk: validate user input for XDP_{UMEM|COMPLETION}_FILL_RING
|
2024-06-16 13:28:52 +02:00 |
|
xfrm
|
xfrm: validate new SA's prefixlen using SA family when sel.family is unset
|
2024-11-08 16:20:52 +01:00 |
|
compat.c
|
|
|
|
Kconfig
|
|
|
|
Makefile
|
|
|
|
socket.c
|
net: Save and restore msg_namelen in sock_sendmsg
|
2024-01-15 18:25:26 +01:00 |
|
sysctl_net.c
|
|
|