mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Greg KH <gregkh@suse.de>
To: linux-kernel@vger.kernel.org, stable@kernel.org
Cc: stable-review@kernel.org, torvalds@linux-foundation.org,
	akpm@linux-foundation.org, alan@lxorguk.ukuu.org.uk,
	"Eric W. Biederman" <ebiederm@xmission.com>,
	"David S. Miller" <davem@davemloft.net>
Subject: [34/43] af_unix: Only allow recv on connected seqpacket sockets.
Date: Thu, 05 May 2011 17:25:55 -0700	[thread overview]
Message-ID: <20110506002610.579762900@clark.kroah.org> (raw)
In-Reply-To: <20110506002625.GA20426@kroah.com>

[-- Warning: decoded text below may be mangled, UTF-8 assumed --]
[-- Attachment #1: Type: text/plain, Size: 2804 bytes --]

2.6.33-longterm review patch.  If anyone has any objections, please let us know.

------------------

From: Eric W. Biederman <ebiederm@xmission.com>

commit a05d2ad1c1f391c7f514a1d1e09b5417968a7d07 upstream.

This fixes the following oops discovered by Dan Aloni:
> Anyway, the following is the output of the Oops that I got on the
> Ubuntu kernel on which I first detected the problem
> (2.6.37-12-generic). The Oops that followed will be more useful, I
> guess.

>[ 5594.669852] BUG: unable to handle kernel NULL pointer dereference
> at           (null)
> [ 5594.681606] IP: [<ffffffff81550b7b>] unix_dgram_recvmsg+0x1fb/0x420
> [ 5594.687576] PGD 2a05d067 PUD 2b951067 PMD 0
> [ 5594.693720] Oops: 0002 [#1] SMP
> [ 5594.699888] last sysfs file:

The bug was that unix domain sockets use a pseduo packet for
connecting and accept uses that psudo packet to get the socket.
In the buggy seqpacket case we were allowing unconnected
sockets to call recvmsg and try to receive the pseudo packet.

That is always wrong and as of commit 7361c36c5 the pseudo
packet had become enough different from a normal packet
that the kernel started oopsing.

Do for seqpacket_recv what was done for seqpacket_send in 2.5
and only allow it on connected seqpacket sockets.

Tested-by: Dan Aloni <dan@aloni.org>
Signed-off-by: Eric W. Biederman <ebiederm@xmission.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>

---
 net/unix/af_unix.c |   16 +++++++++++++++-
 1 file changed, 15 insertions(+), 1 deletion(-)

--- a/net/unix/af_unix.c
+++ b/net/unix/af_unix.c
@@ -503,6 +503,8 @@ static int unix_dgram_connect(struct soc
 			      int, int);
 static int unix_seqpacket_sendmsg(struct kiocb *, struct socket *,
 				  struct msghdr *, size_t);
+static int unix_seqpacket_recvmsg(struct kiocb *, struct socket *,
+				  struct msghdr *, size_t, int);
 
 static const struct proto_ops unix_stream_ops = {
 	.family =	PF_UNIX,
@@ -562,7 +564,7 @@ static const struct proto_ops unix_seqpa
 	.setsockopt =	sock_no_setsockopt,
 	.getsockopt =	sock_no_getsockopt,
 	.sendmsg =	unix_seqpacket_sendmsg,
-	.recvmsg =	unix_dgram_recvmsg,
+	.recvmsg =	unix_seqpacket_recvmsg,
 	.mmap =		sock_no_mmap,
 	.sendpage =	sock_no_sendpage,
 };
@@ -1631,6 +1633,18 @@ static int unix_seqpacket_sendmsg(struct
 	return unix_dgram_sendmsg(kiocb, sock, msg, len);
 }
 
+static int unix_seqpacket_recvmsg(struct kiocb *iocb, struct socket *sock,
+			      struct msghdr *msg, size_t size,
+			      int flags)
+{
+	struct sock *sk = sock->sk;
+
+	if (sk->sk_state != TCP_ESTABLISHED)
+		return -ENOTCONN;
+
+	return unix_dgram_recvmsg(iocb, sock, msg, size, flags);
+}
+
 static void unix_copy_addr(struct msghdr *msg, struct sock *sk)
 {
 	struct unix_sock *u = unix_sk(sk);



  parent reply	other threads:[~2011-05-06  0:27 UTC|newest]

Thread overview: 44+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2011-05-06  0:26 [00/43] 2.6.33.13-longterm review Greg KH
2011-05-06  0:25 ` [01/43] ath: add missing regdomain pair 0x5c mapping Greg KH
2011-05-06  0:25 ` [02/43] block, blk-sysfs: Fix an err return path in blk_register_queue() Greg KH
2011-05-06  0:25 ` [03/43] p54: Initialize extra_len in p54_tx_80211 Greg KH
2011-05-06  0:25 ` [04/43] x86, gart: Make sure GART does not map physmem above 1TB Greg KH
2011-05-06  0:25 ` [05/43] intel-iommu: Unlink domain from iommu Greg KH
2011-05-06  0:25 ` [06/43] intel-iommu: Fix get_domain_for_dev() error path Greg KH
2011-05-06  0:25 ` [07/43] drm/radeon/kms: fix bad shift in atom iio table parser Greg KH
2011-05-06  0:25 ` [08/43] NFS: nfs_wcc_update_inode() should set nfsi->attr_gencount Greg KH
2011-05-06  0:25 ` [09/43] serial/imx: read cts state only after acking cts change irq Greg KH
2011-05-06  0:25 ` [10/43] ASoC: Fix output PGA enabling in wm_hubs CODECs Greg KH
2011-05-06  0:25 ` [11/43] kconfig: Avoid buffer underrun in choice input Greg KH
2011-05-06  0:25 ` [12/43] UBIFS: fix master node recovery Greg KH
2011-05-06  0:25 ` [13/43] Remove extra struct page member from the buffer info structure Greg KH
2011-05-06  0:25 ` [14/43] [S390] dasd: correct device table Greg KH
2011-05-06  0:25 ` [15/43] iwlagn: Support new 5000 microcode Greg KH
2011-05-06  0:25 ` [16/43] udp: Fix bogus UFO packet generation Greg KH
2011-05-06  0:25 ` [17/43] [PARISC] slub: fix panic with DISCONTIGMEM Greg KH
2011-05-06  0:25 ` [18/43] [PARISC] set memory ranges in N_NORMAL_MEMORY when onlined Greg KH
2011-05-06  0:25 ` [19/43] [media] FLEXCOP-PCI: fix __xlate_proc_name-warning for flexcop-pci Greg KH
2011-05-06  0:25 ` [20/43] m68k/mm: Set all online nodes in N_NORMAL_MEMORY Greg KH
2011-05-06  0:25 ` [21/43] nfs: dont lose MS_SYNCHRONOUS on remount of noac mount Greg KH
2011-05-06  0:25 ` [22/43] NFSv4.1: Ensure state manager thread dies on last umount Greg KH
2011-05-06  0:25 ` [23/43] agp: fix arbitrary kernel memory writes Greg KH
2011-05-06  0:25 ` [24/43] agp: fix OOM and buffer overflow Greg KH
2011-05-06  0:25 ` [25/43] Input: xen-kbdfront - fix mouse getting stuck after save/restore Greg KH
2011-05-06  0:25 ` [26/43] [SCSI] pmcraid: reject negative request size Greg KH
2011-05-06  0:25 ` [27/43] [SCSI] mpt2sas: prevent heap overflows and unchecked reads Greg KH
2011-05-06  0:25 ` [28/43] [SCSI] put stricter guards on queue dead checks Greg KH
2011-05-06  0:25 ` [29/43] mmc: sdhci-pci: Fix error case in sdhci_pci_probe_slot() Greg KH
2011-05-06  0:25 ` [30/43] mmc: sdhci: Check mrq->cmd in sdhci_tasklet_finish Greg KH
2011-05-06  0:25 ` [31/43] mmc: sdhci: Check mrq != NULL " Greg KH
2011-05-06  0:25 ` [32/43] USB: fix regression in usbip by setting has_tt flag Greg KH
2011-05-06  0:25 ` [33/43] x86, AMD: Fix APIC timer erratum 400 affecting K8 Rev.A-E processors Greg KH
2011-05-06  0:25 ` Greg KH [this message]
2011-05-06  0:25 ` [35/43] ARM: 6891/1: prevent heap corruption in OABI semtimedop Greg KH
2011-05-06  0:25 ` [36/43] i8k: Tell gcc that *regs gets clobbered Greg KH
2011-05-06  0:25 ` [37/43] Fix gcc 4.5.1 miscompiling drivers/char/i8k.c (again) Greg KH
2011-05-06  0:25 ` [38/43] Open with O_CREAT flag set fails to open existing files on non writable directories Greg KH
2011-05-06  0:26 ` [39/43] can: Add missing socket check in can/bcm release Greg KH
2011-05-06  0:26 ` [40/43] fs/partitions/ldm.c: fix oops caused by corrupted partition table Greg KH
2011-05-06  0:26 ` [41/43] libata: set queue DMA alignment to sector size for ATAPI too Greg KH
2011-05-06  0:26 ` [42/43] usb: musb: core: set has_tt flag Greg KH
2011-05-06  0:26 ` [43/43] iwlwifi: fix skb usage after free Greg KH

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20110506002610.579762900@clark.kroah.org \
    --to=gregkh@suse.de \
    --cc=akpm@linux-foundation.org \
    --cc=alan@lxorguk.ukuu.org.uk \
    --cc=davem@davemloft.net \
    --cc=ebiederm@xmission.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=stable-review@kernel.org \
    --cc=stable@kernel.org \
    --cc=torvalds@linux-foundation.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®