32 lines
1.1 KiB
Diff
32 lines
1.1 KiB
Diff
From: Andrey Konovalov <andreyknvl@google.com>
|
|
Date: Wed, 29 Mar 2017 16:11:21 +0200
|
|
Subject: net/packet: fix overflow in check for tp_frame_nr
|
|
Origin: https://patchwork.ozlabs.org/patch/744812/
|
|
Bug-Debian-Security: https://security-tracker.debian.org/tracker/CVE-2017-7308
|
|
|
|
When calculating rb->frames_per_block * req->tp_block_nr the result
|
|
can overflow.
|
|
|
|
Add a check that tp_block_size * tp_block_nr <= UINT_MAX.
|
|
|
|
Since frames_per_block <= tp_block_size, the expression would
|
|
never overflow.
|
|
|
|
Signed-off-by: Andrey Konovalov <andreyknvl@google.com>
|
|
Acked-by: Eric Dumazet <edumazet@google.com>
|
|
---
|
|
net/packet/af_packet.c | 2 ++
|
|
1 file changed, 2 insertions(+)
|
|
|
|
--- a/net/packet/af_packet.c
|
|
+++ b/net/packet/af_packet.c
|
|
@@ -4247,6 +4247,8 @@ static int packet_set_ring(struct sock *
|
|
rb->frames_per_block = req->tp_block_size / req->tp_frame_size;
|
|
if (unlikely(rb->frames_per_block == 0))
|
|
goto out;
|
|
+ if (unlikely(req->tp_block_size > UINT_MAX / req->tp_block_nr))
|
|
+ goto out;
|
|
if (unlikely((rb->frames_per_block * req->tp_block_nr) !=
|
|
req->tp_frame_nr))
|
|
goto out;
|