projects
/
linux.git
/ commitdiff
commit
grep
author
committer
pickaxe
?
search:
re
summary
|
shortlog
|
log
|
commit
| commitdiff |
tree
raw
|
patch
| inline |
side by side
(parent:
e53ff6e
)
RDMA/addr: Be strict with gid size
author
Leon Romanovsky
<leonro@nvidia.com>
Mon, 5 Apr 2021 07:44:34 +0000
(10:44 +0300)
committer
Greg Kroah-Hartman
<gregkh@linuxfoundation.org>
Wed, 14 Apr 2021 06:42:12 +0000
(08:42 +0200)
[ Upstream commit
d1c803a9ccd7bd3aff5e989ccfb39ed3b799b975
]
The nla_len() is less than or equal to 16. If it's less than 16 then end
of the "gid" buffer is uninitialized.
Fixes:
ae43f8286730
("IB/core: Add IP to GID netlink offload")
Link:
https://lore.kernel.org/r/20210405074434.264221-1-leon@kernel.org
Reported-by: Dan Carpenter <dan.carpenter@oracle.com>
Signed-off-by: Mark Bloch <mbloch@nvidia.com>
Signed-off-by: Leon Romanovsky <leonro@nvidia.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
drivers/infiniband/core/addr.c
patch
|
blob
|
history
diff --git
a/drivers/infiniband/core/addr.c
b/drivers/infiniband/core/addr.c
index
0abce00
..
65e3e7d
100644
(file)
--- a/
drivers/infiniband/core/addr.c
+++ b/
drivers/infiniband/core/addr.c
@@
-76,7
+76,9
@@
static struct workqueue_struct *addr_wq;
static const struct nla_policy ib_nl_addr_policy[LS_NLA_TYPE_MAX] = {
[LS_NLA_TYPE_DGID] = {.type = NLA_BINARY,
- .len = sizeof(struct rdma_nla_ls_gid)},
+ .len = sizeof(struct rdma_nla_ls_gid),
+ .validation_type = NLA_VALIDATE_MIN,
+ .min = sizeof(struct rdma_nla_ls_gid)},
};
static inline bool ib_nl_is_good_ip_resp(const struct nlmsghdr *nlh)