[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <CAHmME9rZ29X=R-quViXaEO_ouxeB2EpzR2bkR93rrN4n--QDqw@mail.gmail.com>
Date: Tue, 25 Apr 2017 17:13:39 +0200
From: "Jason A. Donenfeld" <Jason@...c4.com>
To: Sabrina Dubroca <sd@...asysnail.net>
Cc: Netdev <netdev@...r.kernel.org>,
LKML <linux-kernel@...r.kernel.org>,
David Miller <davem@...emloft.net>, stable@...r.kernel.org,
security@...nel.org
Subject: Re: [PATCH] macsec: avoid heap overflow in skb_to_sgvec
On Tue, Apr 25, 2017 at 5:12 PM, Sabrina Dubroca <sd@...asysnail.net> wrote:
>> https://patchwork.ozlabs.org/patch/754861/
>
> Yes, that prevents the overflow, but now you're just dropping
> packets.
Right, it's a so-called "defense-in-depth" measure.
> I'll review that later, let's fix the overflow without
> breaking connectivity for now.
Agreed.
Powered by blists - more mailing lists