From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qk1-f181.google.com (mail-qk1-f181.google.com [209.85.222.181]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 95C5F3E1717 for ; Tue, 2 Jun 2026 13:36:13 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.222.181 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780407378; cv=none; b=LqgovW45iAGsLuZV4c51KtiPjlV9vZkyO7vkGUDKWBlQHkxFEQVDMgVI9neWER7iqlLTZ629oocWP3aArE72UqisqyXRbGlHSQVnvpbNxTr19pgq/fxdS9I5K/5QF5pFKRWb7TkAm2Ie0wjuPNCM0xOAlGn2NtpzM6Lz/7or9TQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780407378; c=relaxed/simple; bh=7Lj0FqVDmeiNPWCn3u/fKwFl3wYP02Jhmq4tu2IuAwU=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=P/DMn/Ugz7HorGEAGBcDq+UGvDr3KfFfQiQuh55abmID2dBz+A28FfWD07MGH0fMPjVAR0jh0aZ8wt9CdIONUTgu6Sdpg8LRwb1tx88RsvBfiM23mcuwFaPUh6gfTSVF3QUwgQdmJ9TmkKtr81gan+tvZOPVMlc78M7h7/wqi+M= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=jYNmjA1z; arc=none smtp.client-ip=209.85.222.181 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="jYNmjA1z" Received: by mail-qk1-f181.google.com with SMTP id af79cd13be357-915671abd29so186893685a.0 for ; Tue, 02 Jun 2026 06:36:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1780407372; x=1781012172; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=vnT0GMlKGTyqTQGZDUa8kd6IyJCEjxPnkabKrmHLnAA=; b=jYNmjA1zDkh2NmlTK4dNah/TJZGUVPPCNVwZ3oWTVxTXPFJsUitP6RhiSQFbI+MYIq XrUI5zc01dqSEkMRx5JpFXIKsPyLTW45DfQ4wXUK8bTKPLvONyR/2jUzjRDeDYoYKbxi eRwdi4dQm82d4KKZSHcatfq2+yKuiqCdo22SHGMTfBRmfddwQdtHkJwC++t3YI3fgLm0 db28SbKaWYsfCUr2/zPmLvpwwl5KkZFQgpTe72+O4nQstA68uL6rrbKZRLXVRzh9ekm9 lhqejdwD8rg/dRZp08PTBkKp/a92QIYggQliGnSis3wuByRf8EOBx5zLj8OaibGWjq/i GA7Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1780407372; x=1781012172; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=vnT0GMlKGTyqTQGZDUa8kd6IyJCEjxPnkabKrmHLnAA=; b=BUzs+/NPPlcksp6MaXN2CS4t0BmsMLADOLi5EGtXfx0TlMbscPBGZdwdTsgzkD492+ oKqpZvEY1obji2hbP0kzKr54ae1Vrgtjw6QSrzZSjni8m940KhPMDlMW77p2HnKcuwrj YW3q0sU5mBWskYSZpN73p8/n+Miep7YQCzLAi6wviJc1Wj0fCeWMdfqkPsyHOq6MZ7Vw 3f1K9AD+L43cVz0+TNPEwhvJ6Hme13bzO7nH2EgmNxgPBd4KE2dtr+Va+Fi/KXrf6zWr RiW3cBfOwxBOzT6ZeMYq200nrhEfUKS/vmeldV/JggQSLSSF9/10Kq+3mZ0YhO5MhNvY k60g== X-Forwarded-Encrypted: i=1; AFNElJ86oojlTTr6jBOAJpOEJow3itouSKKwZtVPpXxmXoHufO1HnfSaTccGVhDIs72Ys3xd/uy3HBtCMJL8pkA=@vger.kernel.org X-Gm-Message-State: AOJu0YyW1kjfL6i9BX0vw9fEwf4n1S0vLvoQrUNd5NhtFnIc/Z9i/zxz ABD97QZRKqKFz4rEb3YOd789wqBI1z1E9QEq/FfxIz4Amle++HxVTO9i2TIVOSqR X-Gm-Gg: Acq92OFjAFBoEEt3Ij4hyFucm3gol5yi/Z22Vd5AjOq5xzYTeIKLjwtJdrjK6jo6uQk BkHsgeqhpI4C83/TP5uqCZBCtoLPD0PjihFd2a1u42p9QHo2wEyTuHL9M2c5hYb9SiXqf4kULUL khTYG/S3aaPTU2zgZFllyOlFopAhG7RtzvAKtpD/D9qDhcl+oPWfVrUPyX0tzv/DMFEUqHWEZ+d UPV+AWPk5ezgtdwqwKjK0EvokkcFXtTYsHh7k5uqCO5DzBe8z7d6ny1J+OxQTIS/Fa9hvU76dUx ax8cwWFndTD45JBo+P+ZK19lZVCWXgyRGmPj8VHSOh8g01sw4LfsINY/MoQO2di1EFrK/GdYfNg tvA4m1avsqe5v33EQdtsS2DfuKDryYt0EPPtfaT+PoHayJwwDLj5aNuA2+BC3IUv4o7dlffMkC3 nwdZWIIr7Og/K584UKpN/rEjBrK8m5dEy4UyBVGS7B387ie8m0WyhDPIT9XRHfvLRixh1bV25AD EwXzv1Edr5wjyBJQwCJZeVEDMyKio8= X-Received: by 2002:a05:620a:3909:b0:8cd:a3ab:352d with SMTP id af79cd13be357-9153dbabb50mr2601322585a.61.1780407372227; Tue, 02 Jun 2026 06:36:12 -0700 (PDT) Received: from server0 (c-68-48-65-54.hsd1.mi.comcast.net. [68.48.65.54]) by smtp.gmail.com with ESMTPSA id af79cd13be357-915721f7d75sm346036285a.18.2026.06.02.06.36.11 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 02 Jun 2026 06:36:11 -0700 (PDT) From: Michael Bommarito To: Jon Maloy , "David S . Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni Cc: Simon Horman , Ying Xue , netdev@vger.kernel.org, tipc-discussion@lists.sourceforge.net, linux-kernel@vger.kernel.org Subject: [PATCH net 2/4] tipc: validate discovery message length before reading media address Date: Tue, 2 Jun 2026 09:35:53 -0400 Message-ID: <20260602133555.769727-3-michael.bommarito@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260602133555.769727-1-michael.bommarito@gmail.com> References: <20260602133555.769727-1-michael.bommarito@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 7bit tipc_disc_rcv() reads the sender's media address from the fixed media-info area of the header (msg_media_addr(), offset TIPC_MEDIA_INFO_OFFSET) and, when the peer advertises 128-bit node ids, copies a NODE_ID_LEN node id appended after the header. Neither read is bounded against the actual received length: tipc_msg_validate() only enforces a header size in the range [MIN_H_SIZE, MAX_H_SIZE], so a LINK_CONFIG message as short as MIN_H_SIZE (24 bytes) passes validation while the media-address read reaches up to MAX_H_SIZE and the node-id read reaches MAX_H_SIZE + NODE_ID_LEN. A node always builds discovery messages at MAX_H_SIZE + NODE_ID_LEN (tipc_disc_init_msg()), so a shorter LINK_CONFIG message is malformed. Drop such messages before the reads so the media address and node id are taken from received data rather than from uninitialised tail room or memory beyond the buffer. A crafted short LINK_CONFIG datagram otherwise makes tipc_disc_rcv() read past the received message data when a bearer is enabled. Fixes: 3d749a6a26b0 ("tipc: Hide media-specific addressing details from generic bearer code") Assisted-by: Claude:claude-opus-4-7 Signed-off-by: Michael Bommarito --- net/tipc/discover.c | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/net/tipc/discover.c b/net/tipc/discover.c index 3e54d2df5683a..daf5f11fc82b4 100644 --- a/net/tipc/discover.c +++ b/net/tipc/discover.c @@ -217,6 +217,20 @@ void tipc_disc_rcv(struct net *net, struct sk_buff *skb, } hdr = buf_msg(skb); + /* A discovery message carries the sender's media address within the + * fixed-size header and, when 128-bit ids are advertised, a node id + * appended after it. A node always builds these messages at + * MAX_H_SIZE + NODE_ID_LEN, so drop anything too short to hold what + * is read below and keep msg2addr() and the node-id copy within the + * received data. + */ + if (skb->len < MAX_H_SIZE || + ((caps & TIPC_NODE_ID128) && skb->len < MAX_H_SIZE + NODE_ID_LEN)) { + pr_warn_ratelimited("Rcv corrupt discovery message\n"); + kfree_skb(skb); + return; + } + if (caps & TIPC_NODE_ID128) memcpy(peer_id, msg_node_id(hdr), NODE_ID_LEN); else -- 2.53.0