Eric Dumazet
ba6501ea06
slip: make slhc_remember() more robust against malicious packets
[ Upstream commit 7d3fce8cbe3a70a1c7c06c9b53696be5d5d8dd5c ]
syzbot found that slhc_remember() was missing checks against
malicious packets [1].
slhc_remember() only checked the size of the packet was at least 20,
which is not good enough.
We need to make sure the packet includes the IPv4 and TCP header
that are supposed to be carried.
Add iph and th pointers to make the code more readable.
[1]
BUG: KMSAN: uninit-value in slhc_remember+0x2e8/0x7b0 drivers/net/slip/slhc.c:666
slhc_remember+0x2e8/0x7b0 drivers/net/slip/slhc.c:666
ppp_receive_nonmp_frame+0xe45/0x35e0 drivers/net/ppp/ppp_generic.c:2455
ppp_receive_frame drivers/net/ppp/ppp_generic.c:2372 [inline]
ppp_do_recv+0x65f/0x40d0 drivers/net/ppp/ppp_generic.c:2212
ppp_input+0x7dc/0xe60 drivers/net/ppp/ppp_generic.c:2327
pppoe_rcv_core+0x1d3/0x720 drivers/net/ppp/pppoe.c:379
sk_backlog_rcv+0x13b/0x420 include/net/sock.h:1113
__release_sock+0x1da/0x330 net/core/sock.c:3072
release_sock+0x6b/0x250 net/core/sock.c:3626
pppoe_sendmsg+0x2b8/0xb90 drivers/net/ppp/pppoe.c:903
sock_sendmsg_nosec net/socket.c:729 [inline]
__sock_sendmsg+0x30f/0x380 net/socket.c:744
____sys_sendmsg+0x903/0xb60 net/socket.c:2602
___sys_sendmsg+0x28d/0x3c0 net/socket.c:2656
__sys_sendmmsg+0x3c1/0x960 net/socket.c:2742
__do_sys_sendmmsg net/socket.c:2771 [inline]
__se_sys_sendmmsg net/socket.c:2768 [inline]
__x64_sys_sendmmsg+0xbc/0x120 net/socket.c:2768
x64_sys_call+0xb6e/0x3ba0 arch/x86/include/generated/asm/syscalls_64.h:308
do_syscall_x64 arch/x86/entry/common.c:52 [inline]
do_syscall_64+0xcd/0x1e0 arch/x86/entry/common.c:83
entry_SYSCALL_64_after_hwframe+0x77/0x7f
Uninit was created at:
slab_post_alloc_hook mm/slub.c:4091 [inline]
slab_alloc_node mm/slub.c:4134 [inline]
kmem_cache_alloc_node_noprof+0x6bf/0xb80 mm/slub.c:4186
kmalloc_reserve+0x13d/0x4a0 net/core/skbuff.c:587
__alloc_skb+0x363/0x7b0 net/core/skbuff.c:678
alloc_skb include/linux/skbuff.h:1322 [inline]
sock_wmalloc+0xfe/0x1a0 net/core/sock.c:2732
pppoe_sendmsg+0x3a7/0xb90 drivers/net/ppp/pppoe.c:867
sock_sendmsg_nosec net/socket.c:729 [inline]
__sock_sendmsg+0x30f/0x380 net/socket.c:744
____sys_sendmsg+0x903/0xb60 net/socket.c:2602
___sys_sendmsg+0x28d/0x3c0 net/socket.c:2656
__sys_sendmmsg+0x3c1/0x960 net/socket.c:2742
__do_sys_sendmmsg net/socket.c:2771 [inline]
__se_sys_sendmmsg net/socket.c:2768 [inline]
__x64_sys_sendmmsg+0xbc/0x120 net/socket.c:2768
x64_sys_call+0xb6e/0x3ba0 arch/x86/include/generated/asm/syscalls_64.h:308
do_syscall_x64 arch/x86/entry/common.c:52 [inline]
do_syscall_64+0xcd/0x1e0 arch/x86/entry/common.c:83
entry_SYSCALL_64_after_hwframe+0x77/0x7f
CPU: 0 UID: 0 PID: 5460 Comm: syz.2.33 Not tainted 6.12.0-rc2-syzkaller-00006-g87d6aab2389e #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024
Fixes: b5451d783a ("slip: Move the SLIP drivers")
Reported-by: syzbot+2ada1bc857496353be5a@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/netdev/670646db.050a0220.3f80e.0027.GAE@google.com/T/#u
Signed-off-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20241009091132.2136321-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
|
2024-11-08 16:20:46 +01:00 |
| .. |
|
accessibility
|
|
|
|
acpi
|
ACPI: battery: Fix possible crash when unregistering a battery hook
|
2024-11-08 16:20:43 +01:00 |
|
amba
|
|
|
|
android
|
binder: fix UAF caused by offsets overwrite
|
2024-09-12 11:03:55 +02:00 |
|
ata
|
ata: sata_sil: Rename sil_blacklist to sil_quirks
|
2024-11-08 16:20:38 +01:00 |
|
atm
|
atm: idt77252: prevent use after free in dequeue_rx()
|
2024-09-04 13:14:51 +02:00 |
|
auxdisplay
|
|
|
|
base
|
driver core: bus: Return -EIO instead of 0 when show/store invalid bus attribute
|
2024-11-08 16:20:45 +01:00 |
|
bcma
|
|
|
|
block
|
aoe: fix the potential use-after-free problem in more places
|
2024-11-08 16:20:41 +01:00 |
|
bluetooth
|
Bluetooth: btmrvl: Use IRQF_NO_AUTOEN flag in request_irq()
|
2024-11-08 16:20:36 +01:00 |
|
bus
|
bus: tegra-aconnect: Update dependency to ARCH_TEGRA
|
2024-03-26 18:22:15 -04:00 |
|
cdrom
|
|
|
|
char
|
virtio_console: fix misc probe bugs
|
2024-11-08 16:20:43 +01:00 |
|
clk
|
clk: bcm: bcm53573: fix OF node leak in init
|
2024-11-08 16:20:44 +01:00 |
|
clocksource
|
clocksource/drivers/qcom: Add missing iounmap() on errors in msm_dt_timer_init()
|
2024-11-08 16:20:28 +01:00 |
|
connector
|
|
|
|
counter
|
|
|
|
cpufreq
|
cpufreq: exit() callback is optional
|
2024-06-16 13:28:34 +02:00 |
|
cpuidle
|
|
|
|
crypto
|
crypto: qat - Fix ADF_DEV_RESET_SYNC memory leak
|
2024-06-16 13:28:51 +02:00 |
|
dax
|
|
|
|
dca
|
|
|
|
devfreq
|
|
|
|
dio
|
|
|
|
dma
|
dmaengine: ioatdma: Fix missing kmem_cache_destroy()
|
2024-07-05 09:08:23 +02:00 |
|
dma-buf
|
dma-buf/sw-sync: don't enable IRQ from sync_print_obj()
|
2024-06-16 13:28:47 +02:00 |
|
edac
|
EDAC, i10nm: make skx_common.o a separate module
|
2024-08-19 05:33:25 +02:00 |
|
eisa
|
|
|
|
extcon
|
extcon: max8997: select IRQ_DOMAIN instead of depending on it
|
2024-06-16 13:28:43 +02:00 |
|
firewire
|
firewire: nosy: ensure user_length is taken into account when fetching packet contents
|
2024-05-17 11:43:54 +02:00 |
|
firmware
|
firmware: tegra: bpmp: Drop unused mbox_client_to_bpmp()
|
2024-11-08 16:20:39 +01:00 |
|
fpga
|
|
|
|
fsi
|
|
|
|
gnss
|
|
|
|
gpio
|
gpio: aspeed: Use devm_clk api to manage clock source
|
2024-11-08 16:20:45 +01:00 |
|
gpu
|
drm/crtc: fix uninitialized variable use even harder
|
2024-11-08 16:20:43 +01:00 |
|
greybus
|
greybus: Fix use-after-free bug in gb_interface_release due to race condition.
|
2024-07-05 09:08:20 +02:00 |
|
hid
|
HID: cougar: fix slab-out-of-bounds Read in cougar_report_fixup
|
2024-09-12 11:03:54 +02:00 |
|
hsi
|
|
|
|
hv
|
Drivers: hv: vmbus: Fix rescind handling in uio_hv_generic
|
2024-09-12 11:03:55 +02:00 |
|
hwmon
|
hwmon: (ntc_thermistor) fix module autoloading
|
2024-11-08 16:20:28 +01:00 |
|
hwspinlock
|
|
|
|
hwtracing
|
coresight: tmc: sg: Do not leak sg_table
|
2024-11-08 16:20:32 +01:00 |
|
i2c
|
i2c: i801: Use a different adapter-name for IDF adapters
|
2024-11-08 16:20:44 +01:00 |
|
i3c
|
i3c: master: cdns: Update maximum prescaler value for i2c clock
|
2024-02-23 08:25:02 +01:00 |
|
ide
|
|
|
|
idle
|
|
|
|
iio
|
iio: magnetometer: ak8975: Fix reading for ak099xx sensors
|
2024-11-08 16:20:41 +01:00 |
|
infiniband
|
RDMA/rxe: Fix seg fault in rxe_comp_queue_pkt
|
2024-11-08 16:20:45 +01:00 |
|
input
|
Input: synaptics-rmi4 - fix UAF of IRQ domain on driver removal
|
2024-11-08 16:20:43 +01:00 |
|
interconnect
|
interconnect: Treat xlate() returning NULL node as an error
|
2024-01-08 11:29:45 +01:00 |
|
iommu
|
iommu/vt-d: Handle volatile descriptor status read
|
2024-09-12 11:03:53 +02:00 |
|
ipack
|
|
|
|
irqchip
|
irqchip/armada-370-xp: Do not allow mapping IRQ 0 and 1
|
2024-09-12 11:03:52 +02:00 |
|
isdn
|
mISDN: Fix a use after free in hfcmulti_tx()
|
2024-08-19 05:33:42 +02:00 |
|
leds
|
leds: ss4200: Convert PCIBIOS_* return codes to errnos
|
2024-08-19 05:33:37 +02:00 |
|
lightnvm
|
|
|
|
macintosh
|
macintosh/therm_windtunnel: fix module unload.
|
2024-08-19 05:33:34 +02:00 |
|
mailbox
|
mailbox: bcm2835: Fix timeout during suspend mode
|
2024-11-08 16:20:35 +01:00 |
|
mcb
|
mcb: fix error handling for different scenarios when parsing
|
2023-11-28 16:50:19 +00:00 |
|
md
|
dm init: Handle minors larger than 255
|
2024-09-12 11:03:53 +02:00 |
|
media
|
media: videobuf2-core: clear memory related fields in __vb2_plane_dmabuf_put()
|
2024-11-08 16:20:44 +01:00 |
|
memory
|
|
|
|
memstick
|
|
|
|
message
|
|
|
|
mfd
|
mfd: omap-usb-tll: Use struct_size to allocate tll
|
2024-08-19 05:33:32 +02:00 |
|
misc
|
VMCI: Fix use-after-free when removing resource in vmci_resource_remove()
|
2024-09-12 11:03:55 +02:00 |
|
mmc
|
mmc: sdhci-of-aspeed: fix module autoloading
|
2024-09-12 11:03:51 +02:00 |
|
mtd
|
mtd: powernv: Add check devm_kasprintf() returned value
|
2024-11-08 16:20:28 +01:00 |
|
mux
|
|
|
|
net
|
slip: make slhc_remember() more robust against malicious packets
|
2024-11-08 16:20:46 +01:00 |
|
nfc
|
nfc: pn533: Add poll mod list filling check
|
2024-09-04 13:15:04 +02:00 |
|
ntb
|
ntb: ntb_hw_switchtec: Fix use after free vulnerability in switchtec_ntb_remove due to race condition
|
2024-11-08 16:20:44 +01:00 |
|
nubus
|
|
|
|
nvdimm
|
virtio_pmem: Check device status before requesting flush
|
2024-11-08 16:20:44 +01:00 |
|
nvme
|
nvmet-tcp: fix kernel crash if commands allocation fails
|
2024-09-12 11:03:56 +02:00 |
|
nvmem
|
nvmem: Fix return type of devm_nvmem_device_get() in kerneldoc
|
2024-09-12 11:03:55 +02:00 |
|
of
|
of/irq: Support #msi-cells=<0> in of_msi_get_domain
|
2024-11-08 16:20:40 +01:00 |
|
opp
|
|
|
|
oprofile
|
|
|
|
parisc
|
|
|
|
parport
|
dev/parport: fix the array out-of-bounds risk
|
2024-08-19 05:33:43 +02:00 |
|
pci
|
PCI: Mark Creative Labs EMU20k2 INTx masking as broken
|
2024-11-08 16:20:44 +01:00 |
|
pcmcia
|
pcmcia: Use resource_size function on resource object
|
2024-09-12 11:03:52 +02:00 |
|
perf
|
|
|
|
phy
|
phy: ti: phy-omap-usb2: Fix NULL pointer dereference for SRP
|
2024-02-23 08:25:06 +01:00 |
|
pinctrl
|
pinctrl: mvebu: Fix devinit_dove_pinctrl_probe function
|
2024-11-08 16:20:32 +01:00 |
|
platform
|
platform/x86: dell-smbios: Fix error path in dell_smbios_init()
|
2024-09-12 11:03:52 +02:00 |
|
pnp
|
PNP: ACPI: fix fortify warning
|
2024-02-23 08:24:54 +01:00 |
|
power
|
power: reset: brcmstb: Do not go into infinite loop if reset fails
|
2024-11-08 16:20:38 +01:00 |
|
powercap
|
|
|
|
pps
|
pps: add an error check in parport_attach
|
2024-11-08 16:20:35 +01:00 |
|
ps3
|
|
|
|
ptp
|
ptp: Fix error message on failed pin verification
|
2024-07-05 09:08:11 +02:00 |
|
pwm
|
pwm: stm32: Always do lazy disabling
|
2024-08-19 05:33:26 +02:00 |
|
rapidio
|
|
|
|
ras
|
|
|
|
regulator
|
regulator: core: Fix modpost error "regulator_get_regmap" undefined
|
2024-07-05 09:08:23 +02:00 |
|
remoteproc
|
remoteproc: imx_rproc: Skip over memory region when node value is NULL
|
2024-08-19 05:33:44 +02:00 |
|
reset
|
reset: berlin: fix OF node leak in probe() error path
|
2024-11-08 16:20:28 +01:00 |
|
rpmsg
|
rpmsg: virtio: Free driver_override when rpmsg_remove()
|
2024-02-23 08:24:48 +01:00 |
|
rtc
|
rtc: at91sam9: fix OF node leak in probe() error path
|
2024-11-08 16:20:42 +01:00 |
|
s390
|
s390/cio: rename bitmap_size() -> idset_bitmap_size()
|
2024-09-04 13:14:51 +02:00 |
|
sbus
|
|
|
|
scsi
|
scsi: aacraid: Rearrange order of struct aac_srb_unit
|
2024-11-08 16:20:39 +01:00 |
|
sfi
|
|
|
|
sh
|
|
|
|
siox
|
|
|
|
slimbus
|
slimbus: core: Remove usage of the deprecated ida_simple_xx() API
|
2024-04-13 12:51:26 +02:00 |
|
soc
|
soc: versatile: realview: fix soc_dev leak during device remove
|
2024-11-08 16:20:34 +01:00 |
|
soundwire
|
soundwire: stream: Revert "soundwire: stream: fix programming slave ports for non-continous port maps"
|
2024-11-08 16:20:25 +01:00 |
|
spi
|
spi: bcm63xx: Fix module autoloading
|
2024-11-08 16:20:39 +01:00 |
|
spmi
|
|
|
|
ssb
|
ssb: Fix division by zero issue in ssb_calc_clock_rate
|
2024-09-04 13:14:53 +02:00 |
|
staging
|
wifi: wilc1000: fix potential RCU dereference issue in wilc_parse_join_bss_param
|
2024-11-08 16:20:27 +01:00 |
|
target
|
scsi: target: Fix SELinux error when systemd-modules loads the target module
|
2024-05-17 11:43:51 +02:00 |
|
tc
|
|
|
|
tee
|
|
|
|
thermal
|
thermal: core: prevent potential string overflow
|
2023-11-20 10:30:09 +01:00 |
|
thunderbolt
|
|
|
|
tty
|
tty: rp2: Fix reset with non forgiving PCIe host bridges
|
2024-11-08 16:20:33 +01:00 |
|
uio
|
Drivers: hv: vmbus: Fix rescind handling in uio_hv_generic
|
2024-09-12 11:03:55 +02:00 |
|
usb
|
usb: dwc2: Adjust the timing of USB Driver Interrupt Registration in the Crashkernel Scenario
|
2024-11-08 16:20:44 +01:00 |
|
vfio
|
vfio/platform: Create persistent IRQ handlers
|
2024-04-13 12:51:34 +02:00 |
|
vhost
|
vhost: Add smp_rmb() in vhost_vq_avail_empty()
|
2024-05-02 16:18:29 +02:00 |
|
video
|
fbdev: sisfb: Fix strbuf array overflow
|
2024-11-08 16:20:45 +01:00 |
|
virt
|
|
|
|
virtio
|
virtio: delete vq in vp_find_vqs_msix() when request_irq() fails
|
2024-06-16 13:28:46 +02:00 |
|
visorbus
|
|
|
|
vlynq
|
|
|
|
vme
|
|
|
|
w1
|
|
|
|
watchdog
|
watchdog: imx_sc_wdt: Don't disable WDT in suspend
|
2024-11-08 16:20:32 +01:00 |
|
xen
|
xen/swiotlb: add alignment check for dma buffers
|
2024-11-08 16:20:30 +01:00 |
|
zorro
|
|
|
|
Kconfig
|
|
|
|
Makefile
|
|
|