[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <ZNYb2p2hWH1aUyKO@gondor.apana.org.au>
Date: Fri, 11 Aug 2023 19:30:34 +0800
From: Herbert Xu <herbert@...dor.apana.org.au>
To: Mark O'Donovan <shiftee@...teo.net>
Cc: linux-kernel@...r.kernel.org, linux-crypto@...r.kernel.org,
ebiggers@...gle.com
Subject: Re: [PATCH RESEND] lib/mpi: avoid null pointer deref in mpi_cmp_ui()
On Fri, Aug 04, 2023 at 09:32:18AM +0000, Mark O'Donovan wrote:
> During NVMeTCP Authentication a controller can trigger a kernel
> oops by specifying the 8192 bit Diffie Hellman group and passing
> a correctly sized, but zeroed Diffie Hellamn value.
> mpi_cmp_ui() was detecting this if the second parameter was 0,
> but 1 is passed from dh_is_pubkey_valid(). This causes the null
> pointer u->d to be dereferenced towards the end of mpi_cmp_ui()
>
> Signed-off-by: Mark O'Donovan <shiftee@...teo.net>
> ---
> lib/mpi/mpi-cmp.c | 8 ++++++--
> 1 file changed, 6 insertions(+), 2 deletions(-)
Patch applied. Thanks.
--
Email: Herbert Xu <herbert@...dor.apana.org.au>
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt
Powered by blists - more mailing lists