l2tp: prevent tunnel creation on netns mismatch
l2tp_tunnel_create is passed a pointer to the network namespace for the tunnel, along with an optional file descriptor for the tunnel which may be passed in from userspace via. netlink. In the case where the file descriptor is defined, ensure that the namespace associated with that socket matches the namespace explicitly passed to l2tp_tunnel_create. Signed-off-by: Tom Parkin <tparkin@katalix.com> Signed-off-by: James Chapman <jchapman@katalix.com> Signed-off-by: David S. Miller <davem@davemloft.net>
This commit is contained in:
parent
b6fdfdfab0
commit
cbb95e0ca9
@ -1593,11 +1593,18 @@ int l2tp_tunnel_create(struct net *net, int fd, int version, u32 tunnel_id, u32
|
||||
if (err < 0)
|
||||
goto err;
|
||||
} else {
|
||||
err = -EBADF;
|
||||
sock = sockfd_lookup(fd, &err);
|
||||
if (!sock) {
|
||||
pr_err("tunl %hu: sockfd_lookup(fd=%d) returned %d\n",
|
||||
pr_err("tunl %u: sockfd_lookup(fd=%d) returned %d\n",
|
||||
tunnel_id, fd, err);
|
||||
err = -EBADF;
|
||||
goto err;
|
||||
}
|
||||
|
||||
/* Reject namespace mismatches */
|
||||
if (!net_eq(sock_net(sock->sk), net)) {
|
||||
pr_err("tunl %u: netns mismatch\n", tunnel_id);
|
||||
err = -EINVAL;
|
||||
goto err;
|
||||
}
|
||||
}
|
||||
|
Loading…
Reference in New Issue
Block a user