From: Chuck Ebbert <76306.1226@compuserve.com>
To: Bart De Schuymer <bart.de.schuymer@pandora.be>
Cc: Al Viro <viro@ftp.linux.org.uk>,
Patrick McHardy <kaber@trash.net>,
linux-kernel@vger.kernel.org, Dave Jones <davej@redhat.com>,
netdev@vger.kernel.org
Subject: [patch] ebtables: don't compute gap before checking struct type
Date: Tue, 26 Dec 2006 12:54:22 -0500 [thread overview]
Message-ID: <200612261256_MC3-1-D669-14A1@compuserve.com> (raw)
We cannot compute the gap until we know we have a 'struct ebt_entry'
and not 'struct ebt_entries'. Failure to check can cause crash.
Tested by Santiago Garcia Mantinan <manty@manty.net>
Signed-off-by: Chuck Ebbert <76306.1226@compuserve.com>
---
Can we get this upstream quickly? The bug's also in 2.6.19.1 and
2.6.18.6.
--- 2.6.20-rc1-32smp.orig/net/bridge/netfilter/ebtables.c
+++ 2.6.20-rc1-32smp/net/bridge/netfilter/ebtables.c
@@ -610,7 +610,7 @@ ebt_check_entry(struct ebt_entry *e, str
struct ebt_entry_target *t;
struct ebt_target *target;
unsigned int i, j, hook = 0, hookmask = 0;
- size_t gap = e->next_offset - e->target_offset;
+ size_t gap;
int ret;
/* don't mess with the struct ebt_entries */
@@ -660,6 +660,7 @@ ebt_check_entry(struct ebt_entry *e, str
if (ret != 0)
goto cleanup_watchers;
t = (struct ebt_entry_target *)(((char *)e) + e->target_offset);
+ gap = e->next_offset - e->target_offset;
target = find_target_lock(t->u.name, &ret, &ebt_mutex);
if (!target)
goto cleanup_watchers;
--
MBTI: IXTP
reply other threads:[~2006-12-26 18:00 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=200612261256_MC3-1-D669-14A1@compuserve.com \
--to=76306.1226@compuserve.com \
--cc=bart.de.schuymer@pandora.be \
--cc=davej@redhat.com \
--cc=kaber@trash.net \
--cc=linux-kernel@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=viro@ftp.linux.org.uk \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®