[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <ZMzB3t60T9od70Dl@gondor.apana.org.au>
Date: Fri, 4 Aug 2023 17:16:14 +0800
From: Herbert Xu <herbert@...dor.apana.org.au>
To: Mark O'Donovan <shiftee@...teo.net>
Cc: linux-kernel@...r.kernel.org, ebiggers@...gle.com
Subject: Re: [PATCH] lib/mpi: avoid null pointer deref in mpi_cmp_ui()
On Mon, Jul 24, 2023 at 12:07:27AM +0000, Mark O'Donovan wrote:
> During NVMeTCP Authentication a controller can trigger a kernel
> oops by specifying the 8192 bit Diffie Hellman group and passing
> a correctly sized, but zeroed Diffie Hellamn value.
> mpi_cmp_ui() was detecting this if the second parameter was 0,
> but 1 is passed from dh_is_pubkey_valid(). This causes the null
> pointer u->d to be dereferenced towards the end of mpi_cmp_ui()
>
> Signed-off-by: Mark O'Donovan <shiftee@...teo.net>
> ---
> lib/mpi/mpi-cmp.c | 8 ++++++--
> 1 file changed, 6 insertions(+), 2 deletions(-)
Could you please resend this to linux-crypto?
Thanks,
--
Email: Herbert Xu <herbert@...dor.apana.org.au>
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt
Powered by blists - more mailing lists