lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite for Android: free password hash cracker in your pocket
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-Id: <20180124.165333.969468268744049786.davem@davemloft.net>
Date:   Wed, 24 Jan 2018 16:53:33 -0500 (EST)
From:   David Miller <davem@...emloft.net>
To:     u9012063@...il.com
Cc:     netdev@...r.kernel.org
Subject: Re: [PATCH net] net: erspan: fix use-after-free

From: William Tu <u9012063@...il.com>
Date: Tue, 23 Jan 2018 17:01:29 -0800

> When building the erspan header for either v1 or v2, the eth_hdr()
> does not point to the right inner packet's eth_hdr,
> causing kasan report use-after-free and slab-out-of-bouds read.
 ...
> Fixes: f551c91de262 ("net: erspan: introduce erspan v2 for ip_gre")
> Fixes: 84e54fe0a5ea ("gre: introduce native tunnel support for ERSPAN")
> Reported-by: syzbot+9723f2d288e49b492cf0@...kaller.appspotmail.com
> Reported-by: syzbot+f0ddeb2b032a8e1d9098@...kaller.appspotmail.com
> Reported-by: syzbot+f14b3703cd8d7670203f@...kaller.appspotmail.com
> Reported-by: syzbot+eefa384efad8d7997f20@...kaller.appspotmail.com
> Signed-off-by: William Tu <u9012063@...il.com>

Applied to net-next.

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ