tcp: fix 0 divide in __tcp_select_window()
syszkaller fuzzer was able to trigger a divide by zero, when TCP window scaling is not enabled. SO_RCVBUF can be used not only to increase sk_rcvbuf, also to decrease it below current receive buffers utilization. If mss is negative or 0, just return a zero TCP window. Signed-off-by: Eric Dumazet <edumazet@google.com> Reported-by: Dmitry Vyukov <dvyukov@google.com> Acked-by: Neal Cardwell <ncardwell@google.com> Signed-off-by: David S. Miller <davem@davemloft.net>
This commit is contained in:
parent
63117f09c7
commit
06425c308b
@ -2518,9 +2518,11 @@ u32 __tcp_select_window(struct sock *sk)
|
|||||||
int full_space = min_t(int, tp->window_clamp, allowed_space);
|
int full_space = min_t(int, tp->window_clamp, allowed_space);
|
||||||
int window;
|
int window;
|
||||||
|
|
||||||
if (mss > full_space)
|
if (unlikely(mss > full_space)) {
|
||||||
mss = full_space;
|
mss = full_space;
|
||||||
|
if (mss <= 0)
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
if (free_space < (full_space >> 1)) {
|
if (free_space < (full_space >> 1)) {
|
||||||
icsk->icsk_ack.quick = 0;
|
icsk->icsk_ack.quick = 0;
|
||||||
|
|
||||||
|
Loading…
Reference in New Issue
Block a user