[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-Id: <20170504.110745.1166031278249644101.davem@davemloft.net>
Date: Thu, 04 May 2017 11:07:45 -0400 (EDT)
From: David Miller <davem@...emloft.net>
To: glider@...gle.com
Cc: dvyukov@...gle.com, kcc@...gle.com, edumazet@...gle.com,
kuznet@....inr.ac.ru, linux-kernel@...r.kernel.org,
netdev@...r.kernel.org
Subject: Re: [PATCH] ipv4, ipv6: ensure raw socket message is big enough to
hold an IP header
From: Alexander Potapenko <glider@...gle.com>
Date: Wed, 3 May 2017 17:06:58 +0200
> raw_send_hdrinc() and rawv6_send_hdrinc() expect that the buffer copied
> from the userspace contains the IPv4/IPv6 header, so if too few bytes are
> copied, parts of the header may remain uninitialized.
>
> This bug has been detected with KMSAN.
>
> Signed-off-by: Alexander Potapenko <glider@...gle.com>
Applied and queued up for -stable, thanks.
Powered by blists - more mailing lists