lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date:	Sat, 27 Mar 2010 10:34:07 -0700 (PDT)
From:	David Miller <davem@...emloft.net>
To:	michael.s.gilbert@...il.com
Cc:	linux-kernel@...r.kernel.org
Subject: Re: CVE-2009-4537

From: Michael Gilbert <michael.s.gilbert@...il.com>
Date: Sat, 27 Mar 2010 14:21:00 -0400

> Hi,
> 
> CVE-2009-4537 has been disclosed without any upstream activity for a
> while now. Discussion about the issue dried up in January [0], and a
> patch had been proposed [1], but no arguments were seen either for or
> against it. Note that redhat has already shipped that in their various
> kernel security updates.  Would it make sense to merge those changes
> officially?

A different version of the fix went into the tree.

commit 8812304cf1110ae16b0778680f6022216cf4716a
Author: Raimonds Cicans <ray@...llo.lv>
Date:   Fri Nov 13 10:52:19 2009 +0000

    r8169: Fix receive buffer length when MTU is between 1515 and 1536
    
    In r8169 driver MTU is used to calculate receive buffer size.
    Receive buffer size is used to configure hardware incoming packet filter.
    
    For jumbo frames:
    Receive buffer size = Max frame size = MTU + 14 (ethernet header) + 4
    (vlan header) + 4 (ethernet checksum) = MTU + 22
    
    Bug:
    driver for all MTU up to 1536 use receive buffer size 1536
    
    As you can see from formula, this mean all IP packets > 1536 - 22
    (for vlan tagged, 1536 - 18 for not tagged) are dropped by hardware
    filter.
    
    Example:
    
    host_good>  ifconfig eth0 mtu 1536
    host_r8169> ifconfig eth0 mtu 1536
    host_good>  ping host_r8169
    Ok
    host_good>  ping -s 1500 host_r8169
    Fail
    host_good>  ifconfig eth0 mtu 7000
    host_r8169> ifconfig eth0 mtu 7000
    host_good>  ping -s 1500 host_r8169
    Ok
    
    Bonus: got rid of magic number 8
    
    Signed-off-by: Raimonds Cicans <ray@...llo.lv>
    Signed-off-by: David S. Miller <davem@...emloft.net>

diff --git a/drivers/net/r8169.c b/drivers/net/r8169.c
index fa49356..b9221bd 100644
--- a/drivers/net/r8169.c
+++ b/drivers/net/r8169.c
@@ -3243,9 +3243,9 @@ static void __devexit rtl8169_remove_one(struct pci_dev *pdev)
 static void rtl8169_set_rxbufsize(struct rtl8169_private *tp,
 				  struct net_device *dev)
 {
-	unsigned int mtu = dev->mtu;
+	unsigned int max_frame = dev->mtu + VLAN_ETH_HLEN + ETH_FCS_LEN;
 
-	tp->rx_buf_sz = (mtu > RX_BUF_SIZE) ? mtu + ETH_HLEN + 8 : RX_BUF_SIZE;
+	tp->rx_buf_sz = (max_frame > RX_BUF_SIZE) ? max_frame : RX_BUF_SIZE;
 }
 
 static int rtl8169_open(struct net_device *dev)
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@...r.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ