From: Karsten Keil <kkeil@suse.de>
To: Linux Kernel <linux-kernel@vger.kernel.org>
Cc: torvalds@osdl.org, akpm@osdl.org
Subject: BUG Fix for PPP activ/passiv filter in 2.6
Date: Sat, 14 Feb 2004 17:23:28 +0100 [thread overview]
Message-ID: <20040214162328.GA5931@pingi3.kke.suse.de> (raw)
Hi all,
I found a bug in the PPPIOCSPASS PPPIOCSACTIVE IOCTL implementation in
kernel 2.5/2.6.
The current pppd code use a empty filter (uprog.len=0) to detach the filter
in the kernel, but this code was removed in 2.5.71 while fixing a compiler
warning.
Here the new patch, also with better limit checking.
The second patch check for flen == 0 in the filter check too, since later in
this code a filter[flen - 1] access is done, which is not so funny with flen
0. Maybe it's not really needed anymore, since with the first patch it would
not longer called with flen=0.
diff -urN linux-2.6.3-rc2-bk4.org/drivers/net/ppp_generic.c linux-2.6.3-rc2-bk4/drivers/net/ppp_generic.c
--- linux-2.6.3-rc2-bk4.org/drivers/net/ppp_generic.c 2004-02-11 15:31:33.000000000 +0100
+++ linux-2.6.3-rc2-bk4/drivers/net/ppp_generic.c 2004-02-14 16:39:39.000000000 +0100
@@ -675,20 +675,25 @@
if (copy_from_user(&uprog, (void __user *) arg, sizeof(uprog)))
break;
- err = -ENOMEM;
- len = uprog.len * sizeof(struct sock_filter);
- code = kmalloc(len, GFP_KERNEL);
- if (code == 0)
- break;
- err = -EFAULT;
- if (copy_from_user(code, (void __user *) uprog.filter, len)) {
- kfree(code);
- break;
- }
- err = sk_chk_filter(code, uprog.len);
- if (err) {
- kfree(code);
+ err = -EINVAL;
+ if (uprog.len > BPF_MAXINSNS)
break;
+ err = -ENOMEM;
+ if (uprog.len > 0) {
+ len = uprog.len * sizeof(struct sock_filter);
+ code = kmalloc(len, GFP_KERNEL);
+ if (code == NULL)
+ break;
+ err = -EFAULT;
+ if (copy_from_user(code, (void __user *) uprog.filter, len)) {
+ kfree(code);
+ break;
+ }
+ err = sk_chk_filter(code, uprog.len);
+ if (err) {
+ kfree(code);
+ break;
+ }
}
filtp = (cmd == PPPIOCSPASS)? &ppp->pass_filter: &ppp->active_filter;
ppp_lock(ppp);
diff -urN linux-2.6.3-rc2-bk4.org/net/core/filter.c linux-2.6.3-rc2-bk4/net/core/filter.c
--- linux-2.6.3-rc2-bk4.org/net/core/filter.c 2003-12-18 03:58:39.000000000 +0100
+++ linux-2.6.3-rc2-bk4/net/core/filter.c 2004-02-14 16:39:39.000000000 +0100
@@ -332,7 +332,7 @@
struct sock_filter *ftest;
int pc;
- if ((unsigned int)flen >= (~0U / sizeof(struct sock_filter)))
+ if (((unsigned int)flen >= (~0U / sizeof(struct sock_filter))) || flen == 0)
return -EINVAL;
/* check the filter code now */
--
Karsten Keil
SuSE Labs
ISDN development
reply other threads:[~2004-02-14 16:25 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20040214162328.GA5931@pingi3.kke.suse.de \
--to=kkeil@suse.de \
--cc=akpm@osdl.org \
--cc=linux-kernel@vger.kernel.org \
--cc=torvalds@osdl.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®