mirror of
https://github.com/raspberrypi/linux.git
synced 2025-12-06 01:49:46 +00:00
netlink: add nla be16/32 types to minlen array
[ Upstream commit9a0d18853c] BUG: KMSAN: uninit-value in nla_validate_range_unsigned lib/nlattr.c:222 [inline] BUG: KMSAN: uninit-value in nla_validate_int_range lib/nlattr.c:336 [inline] BUG: KMSAN: uninit-value in validate_nla lib/nlattr.c:575 [inline] BUG: KMSAN: uninit-value in __nla_validate_parse+0x2e20/0x45c0 lib/nlattr.c:631 nla_validate_range_unsigned lib/nlattr.c:222 [inline] nla_validate_int_range lib/nlattr.c:336 [inline] validate_nla lib/nlattr.c:575 [inline] ... The message in question matches this policy: [NFTA_TARGET_REV] = NLA_POLICY_MAX(NLA_BE32, 255), but because NLA_BE32 size in minlen array is 0, the validation code will read past the malformed (too small) attribute. Note: Other attributes, e.g. BITFIELD32, SINT, UINT.. are also missing: those likely should be added too. Reported-by: syzbot+3f497b07aa3baf2fb4d0@syzkaller.appspotmail.com Reported-by: xingwei lee <xrivendell7@gmail.com> Closes: https://lore.kernel.org/all/CABOYnLzFYHSnvTyS6zGa-udNX55+izqkOt2sB9WDqUcEGW6n8w@mail.gmail.com/raw Fixes:ecaf75ffd5("netlink: introduce bigendian integer types") Signed-off-by: Florian Westphal <fw@strlen.de> Link: https://lore.kernel.org/r/20240221172740.5092-1-fw@strlen.de Signed-off-by: Jakub Kicinski <kuba@kernel.org> Signed-off-by: Sasha Levin <sashal@kernel.org>
This commit is contained in:
committed by
Greg Kroah-Hartman
parent
0b27bf4c49
commit
0ac219c4c3
@@ -30,6 +30,8 @@ static const u8 nla_attr_len[NLA_TYPE_MAX+1] = {
|
|||||||
[NLA_S16] = sizeof(s16),
|
[NLA_S16] = sizeof(s16),
|
||||||
[NLA_S32] = sizeof(s32),
|
[NLA_S32] = sizeof(s32),
|
||||||
[NLA_S64] = sizeof(s64),
|
[NLA_S64] = sizeof(s64),
|
||||||
|
[NLA_BE16] = sizeof(__be16),
|
||||||
|
[NLA_BE32] = sizeof(__be32),
|
||||||
};
|
};
|
||||||
|
|
||||||
static const u8 nla_attr_minlen[NLA_TYPE_MAX+1] = {
|
static const u8 nla_attr_minlen[NLA_TYPE_MAX+1] = {
|
||||||
@@ -43,6 +45,8 @@ static const u8 nla_attr_minlen[NLA_TYPE_MAX+1] = {
|
|||||||
[NLA_S16] = sizeof(s16),
|
[NLA_S16] = sizeof(s16),
|
||||||
[NLA_S32] = sizeof(s32),
|
[NLA_S32] = sizeof(s32),
|
||||||
[NLA_S64] = sizeof(s64),
|
[NLA_S64] = sizeof(s64),
|
||||||
|
[NLA_BE16] = sizeof(__be16),
|
||||||
|
[NLA_BE32] = sizeof(__be32),
|
||||||
};
|
};
|
||||||
|
|
||||||
/*
|
/*
|
||||||
|
|||||||
Reference in New Issue
Block a user