From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S965062AbcA1OA4 (ORCPT ); Thu, 28 Jan 2016 09:00:56 -0500 Received: from mail-pa0-f67.google.com ([209.85.220.67]:35907 "EHLO mail-pa0-f67.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S933788AbcA1OAx (ORCPT ); Thu, 28 Jan 2016 09:00:53 -0500 Message-ID: <1453989650.7627.30.camel@edumazet-glaptop2.roam.corp.google.com> Subject: Re: Re: [PATCH V2] netfilter: h323: avoid potential attack From: Eric Dumazet To: Zhouyi Zhou Cc: Zhouyi Zhou , pablo@netfilter.org, kaber@trash.net, kadlec@blackhole.kfki.hu, davem@davemloft.net, netfilter-devel@vger.kernel.org, coreteam@netfilter.org, netdev@vger.kernel.org, linux-kernel@vger.kernel.org Date: Thu, 28 Jan 2016 06:00:50 -0800 In-Reply-To: References: <1453971597-4811-1-git-send-email-zhouzhouyi@gmail.com> <1453985821.7627.17.camel@edumazet-glaptop2.roam.corp.google.com> Content-Type: text/plain; charset="UTF-8" X-Mailer: Evolution 3.10.4-0ubuntu2 Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Thu, 2016-01-28 at 21:14 +0800, Zhouyi Zhou wrote: > My patch is intend to prevent kernel panic, to prevent reading garbage > or read data from a prior frame and leak secrets, the prototypes of the > get_h2x5_addr functions and the functions that call get_h2x5_addr should > be changed, should we do this? In term of security, panics are better than allowing attacker to read data from other people, like a password. BTW, are you able to trigger any panic ? I am not familiar with this code, it is not obvious. If a fix is needed, better doing it right.