Sean Tranchetti
5217bec5a6
xfrm: validate template mode
...
[ Upstream commit 32bf94fb5c2ec4ec842152d0e5937cd4bb6738fa ]
XFRM mode parameters passed as part of the user templates
in the IP_XFRM_POLICY are never properly validated. Passing
values other than valid XFRM modes can cause stack-out-of-bounds
reads to occur later in the XFRM processing:
[ 140.535608] ================================================================
[ 140.543058] BUG: KASAN: stack-out-of-bounds in xfrm_state_find+0x17e4/0x1cc4
[ 140.550306] Read of size 4 at addr ffffffc0238a7a58 by task repro/5148
[ 140.557369]
[ 140.558927] Call trace:
[ 140.558936] dump_backtrace+0x0/0x388
[ 140.558940] show_stack+0x24/0x30
[ 140.558946] __dump_stack+0x24/0x2c
[ 140.558949] dump_stack+0x8c/0xd0
[ 140.558956] print_address_description+0x74/0x234
[ 140.558960] kasan_report+0x240/0x264
[ 140.558963] __asan_report_load4_noabort+0x2c/0x38
[ 140.558967] xfrm_state_find+0x17e4/0x1cc4
[ 140.558971] xfrm_resolve_and_create_bundle+0x40c/0x1fb8
[ 140.558975] xfrm_lookup+0x238/0x1444
[ 140.558977] xfrm_lookup_route+0x48/0x11c
[ 140.558984] ip_route_output_flow+0x88/0xc4
[ 140.558991] raw_sendmsg+0xa74/0x266c
[ 140.558996] inet_sendmsg+0x258/0x3b0
[ 140.559002] sock_sendmsg+0xbc/0xec
[ 140.559005] SyS_sendto+0x3a8/0x5a8
[ 140.559008] el0_svc_naked+0x34/0x38
[ 140.559009]
[ 140.592245] page dumped because: kasan: bad access detected
[ 140.597981] page_owner info is not active (free page?)
[ 140.603267]
[ 140.653503] ================================================================
Signed-off-by: Sean Tranchetti <stranche@codeaurora.org>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2018-11-10 07:41:33 -08:00
..
2018-10-10 08:52:04 +02:00
2018-09-15 09:40:39 +02:00
2018-04-13 19:50:25 +02:00
2018-05-16 10:06:51 +02:00
2017-02-04 09:45:09 +01:00
2018-05-30 07:49:06 +02:00
2018-09-19 22:48:58 +02:00
2018-10-13 09:11:35 +02:00
2018-09-05 09:18:34 +02:00
2018-01-31 12:06:08 +01:00
2018-05-02 07:53:42 -07:00
2018-10-20 09:52:37 +02:00
2018-09-19 22:48:58 +02:00
2018-08-22 07:48:35 +02:00
2018-02-25 11:03:38 +01:00
2018-07-22 14:25:54 +02:00
2018-08-06 16:24:41 +02:00
2017-02-18 16:39:27 +01:00
2015-11-23 14:56:15 -05:00
2018-09-09 20:04:32 +02:00
2018-10-20 09:52:36 +02:00
2018-11-10 07:41:32 -08:00
2017-05-25 14:30:13 +02:00
2018-09-15 09:40:40 +02:00
2018-03-31 18:12:33 +02:00
2018-06-16 09:54:25 +02:00
2018-08-22 07:48:35 +02:00
2015-10-07 04:27:43 -07:00
2018-08-22 07:48:35 +02:00
2018-11-10 07:41:33 -08:00
2018-09-09 20:04:32 +02:00
2018-03-11 16:19:47 +01:00
2018-09-19 22:48:59 +02:00
2018-10-20 09:52:36 +02:00
2018-08-09 12:19:28 +02:00
2018-09-29 03:08:51 -07:00
2018-05-26 08:48:47 +02:00
2018-08-24 13:27:01 +02:00
2016-01-31 11:29:00 -08:00
2018-07-22 14:25:54 +02:00
2018-05-16 10:06:51 +02:00
2015-06-24 02:58:51 -07:00
2018-04-13 19:50:23 +02:00
2018-09-15 09:40:42 +02:00
2018-05-26 08:48:49 +02:00
2018-04-24 09:32:11 +02:00
2016-06-24 10:18:16 -07:00
2018-04-29 07:50:06 +02:00
2017-11-18 11:11:06 +01:00
2018-08-22 07:48:35 +02:00
2015-08-09 22:43:52 -07:00
2018-11-10 07:41:33 -08:00
2018-04-13 19:50:07 +02:00
2018-11-10 07:41:33 -08:00
2018-05-26 08:48:47 +02:00
2018-02-25 11:03:37 +01:00
2015-09-29 20:40:32 -07:00
2018-08-06 16:24:42 +02:00
2016-09-15 08:27:50 +02:00