summary |
shortlog |
log |
commit | commitdiff |
tree
raw |
patch |
inline | side by side (from parent 1:
2897cbb)
The problem is that we copy hdr.ioc_len, we verify it, then we copy it
again without checking to see if it has changed in between the two
copies.
This could result in an information leak.
Linux-commit:
76bdaa161cd93d9c033bf6fe2b0a5661c8204441
Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: James Simmons <uja.ornl@yahoo.com>
Change-Id: Ic9ae8c19d90a5547600f3775ed337394717b94e3
Reviewed-on: https://review.whamcloud.com/35574
Tested-by: jenkins <devops@whamcloud.com>
Tested-by: Maloo <maloo@whamcloud.com>
Reviewed-by: Shaun Tancheff <stancheff@cray.com>
Reviewed-by: Andreas Dilger <adilger@whamcloud.com>
Reviewed-by: Neil Brown <neilb@suse.de>
Reviewed-by: Oleg Drokin <green@whamcloud.com>
struct libcfs_ioctl_hdr __user *uhdr)
{
struct libcfs_ioctl_hdr hdr;
struct libcfs_ioctl_hdr __user *uhdr)
{
struct libcfs_ioctl_hdr hdr;
ENTRY;
if (copy_from_user(&hdr, uhdr, sizeof(hdr)))
ENTRY;
if (copy_from_user(&hdr, uhdr, sizeof(hdr)))
RETURN(-ENOMEM);
if (copy_from_user(*hdr_pp, uhdr, hdr.ioc_len))
RETURN(-ENOMEM);
if (copy_from_user(*hdr_pp, uhdr, hdr.ioc_len))
- GOTO(failed, err = -EFAULT);
+ GOTO(free, err = -EFAULT);
+
+ if ((*hdr_pp)->ioc_version != hdr.ioc_version ||
+ (*hdr_pp)->ioc_len != hdr.ioc_len) {
+ GOTO(free, err = -EINVAL);
+ }
LIBCFS_FREE(*hdr_pp, hdr.ioc_len);
RETURN(err);
}
LIBCFS_FREE(*hdr_pp, hdr.ioc_len);
RETURN(err);
}