lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <Yz86njFh5pfpVwPS@shredder> Date: Thu, 6 Oct 2022 23:29:18 +0300 From: Ido Schimmel <idosch@...sch.org> To: David Ahern <dsahern@...nel.org> Cc: kuba@...nel.org, davem@...emloft.net, pabeni@...hat.com, netdev@...r.kernel.org, Gwangun Jung <exsociety@...il.com> Subject: Re: [PATCH v3 net] ipv4: Handle attempt to delete multipath route when fib_info contains an nh reference On Thu, Oct 06, 2022 at 10:48:49AM -0600, David Ahern wrote: > Gwangun Jung reported a slab-out-of-bounds access in fib_nh_match: > fib_nh_match+0xf98/0x1130 linux-6.0-rc7/net/ipv4/fib_semantics.c:961 > fib_table_delete+0x5f3/0xa40 linux-6.0-rc7/net/ipv4/fib_trie.c:1753 > inet_rtm_delroute+0x2b3/0x380 linux-6.0-rc7/net/ipv4/fib_frontend.c:874 > > Separate nexthop objects are mutually exclusive with the legacy > multipath spec. Fix fib_nh_match to return if the config for the > to be deleted route contains a multipath spec while the fib_info > is using a nexthop object. > > Fixes: 493ced1ac47c ("ipv4: Allow routes to use nexthop objects") > Fixes: 6bf92d70e690 ("net: ipv4: fix route with nexthop object delete warning") > Reported-by: Gwangun Jung <exsociety@...il.com> > Signed-off-by: David Ahern <dsahern@...nel.org> Reviewed-by: Ido Schimmel <idosch@...dia.com> Tested-by: Ido Schimmel <idosch@...dia.com>
Powered by blists - more mailing lists