net: af_key: fix sadb_x_filter validation
[ Upstream commit75065a8929
] When running xfrm_state_walk_init(), the xfrm_address_filter being used is okay to have a splen/dplen that equals to sizeof(xfrm_address_t)<<3. This commit replaces >= to > to make sure the boundary checking is correct. Fixes:37bd22420f
("af_key: pfkey_dump needs parameter validation") Signed-off-by: Lin Ma <linma@zju.edu.cn> Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com> Signed-off-by: Sasha Levin <sashal@kernel.org>
This commit is contained in:
parent
9a0056276f
commit
479884b4ce
|
@ -1848,9 +1848,9 @@ static int pfkey_dump(struct sock *sk, struct sk_buff *skb, const struct sadb_ms
|
||||||
if (ext_hdrs[SADB_X_EXT_FILTER - 1]) {
|
if (ext_hdrs[SADB_X_EXT_FILTER - 1]) {
|
||||||
struct sadb_x_filter *xfilter = ext_hdrs[SADB_X_EXT_FILTER - 1];
|
struct sadb_x_filter *xfilter = ext_hdrs[SADB_X_EXT_FILTER - 1];
|
||||||
|
|
||||||
if ((xfilter->sadb_x_filter_splen >=
|
if ((xfilter->sadb_x_filter_splen >
|
||||||
(sizeof(xfrm_address_t) << 3)) ||
|
(sizeof(xfrm_address_t) << 3)) ||
|
||||||
(xfilter->sadb_x_filter_dplen >=
|
(xfilter->sadb_x_filter_dplen >
|
||||||
(sizeof(xfrm_address_t) << 3))) {
|
(sizeof(xfrm_address_t) << 3))) {
|
||||||
mutex_unlock(&pfk->dump_lock);
|
mutex_unlock(&pfk->dump_lock);
|
||||||
return -EINVAL;
|
return -EINVAL;
|
||||||
|
|
Loading…
Reference in New Issue