From: Johannes Berg <johannes@sipsolutions.net>
To: David Miller <davem@davemloft.net>
Cc: daniel@caiaq.de, linux-kernel@vger.kernel.org, dcbw@redhat.com,
m.hirsch@raumfeld.com, netdev@vger.kernel.org,
libertas-dev@lists.infradead.org, stable@kernel.org,
linux-wireless@vger.kernel.org
Subject: Re: [PATCH] wireless: wext: allocate space for NULL-termination for 32byte SSIDs
Date: Tue, 15 Dec 2009 11:03:31 +0100 [thread overview]
Message-ID: <1260871411.3692.4.camel@johannes.local> (raw)
In-Reply-To: <20091215.014308.77044043.davem@davemloft.net>
[-- Attachment #1: Type: text/plain, Size: 1871 bytes --]
On Tue, 2009-12-15 at 01:43 -0800, David Miller wrote:
> > The effect is that after a number of mode transistions (sometimes as few
> > as two sufficed), the kernel will oops at very strange locations, mostly
> > in something like __kmem_alloc().
> >
> > While the root cause turned out to be an issue with the wpa-supplicant
> > which feeds the kernel driver with garbage, this occasion pointed out a
> > bug in the wireless wext core when SSIDs with 32 byte lengths are passed
> > from userspace. In this case, the string is not properly NULL-terminated
> > which causes some other part to corrupt memory.
> >
> > (In the particular case I observed, an SIOCSIWESSID was issued with
> > bogus data in iwp->pointer but iwp->length=32).
> >
> > I admitedly couldn't find where the actual corruption itself happens,
> > but with this trivial fix, I can't reproduce the bug anymore.
Well you should try harder :)
> > - /* kzalloc() ensures NULL-termination for essid_compat. */
> > - extra = kzalloc(extra_size, GFP_KERNEL);
> > + /* kzalloc() +1 ensures NULL-termination for essid_compat. */
> > + extra = kzalloc(extra_size + 1, GFP_KERNEL);
That doesn't seem correct.
If this is used in a SET, then it is purely an in-kernel thing and
everything in the kernel is passed the length + data, and the kernel
MUST NEVER treat the SSID as a NUL-terminated string.
If this is used in a GET, then it will be filled up to 32 bytes by the
get handler, and the trailing \0 your patch reserves will never be
copied into userspace.
Since you indicate the kernel crashed, it is likely that libertas is
treating the buffer as a string, instead of an SSID.
That doesn't, however, make your fix and more valid. Whatever code uses
it as a string is clearly at fault, since this is a valid four-byte
SSID: "\x00\x01\x02\x03"
johannes
[-- Attachment #2: This is a digitally signed message part --]
[-- Type: application/pgp-signature, Size: 801 bytes --]
next prev parent reply other threads:[~2009-12-15 10:04 UTC|newest]
Thread overview: 17+ messages / expand[flat|nested] mbox.gz Atom feed top
2009-12-12 20:47 Daniel Mack
2009-12-15 9:43 ` David Miller
2009-12-15 10:03 ` Johannes Berg [this message]
2009-12-15 10:05 ` Johannes Berg
2009-12-15 10:07 ` Johannes Berg
2009-12-15 10:20 ` Daniel Mack
2009-12-15 10:31 ` Johannes Berg
2009-12-15 10:37 ` Daniel Mack
2009-12-15 10:30 ` Holger Schurig
2009-12-15 10:35 ` Johannes Berg
2009-12-16 6:54 ` Albert Cahalan
2009-12-16 8:19 ` Johannes Berg
2009-12-16 8:26 ` Holger Schurig
2009-12-16 3:58 ` Daniel Mack
2009-12-16 8:20 ` Johannes Berg
2009-12-15 10:16 ` Albert Cahalan
2009-12-15 16:29 ` Marcel Holtmann
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1260871411.3692.4.camel@johannes.local \
--to=johannes@sipsolutions.net \
--cc=daniel@caiaq.de \
--cc=davem@davemloft.net \
--cc=dcbw@redhat.com \
--cc=libertas-dev@lists.infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-wireless@vger.kernel.org \
--cc=m.hirsch@raumfeld.com \
--cc=netdev@vger.kernel.org \
--cc=stable@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®