lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <SJ1PR11MB629726A0C8891B756CF0DFD09B89A@SJ1PR11MB6297.namprd11.prod.outlook.com>
Date: Tue, 6 May 2025 22:10:39 +0000
From: "Salin, Samuel" <samuel.salin@...el.com>
To: "Linga, Pavan Kumar" <pavan.kumar.linga@...el.com>,
	"intel-wired-lan@...ts.osuosl.org" <intel-wired-lan@...ts.osuosl.org>
CC: "netdev@...r.kernel.org" <netdev@...r.kernel.org>, "Linga, Pavan Kumar"
	<pavan.kumar.linga@...el.com>, "Chittim, Madhu" <madhu.chittim@...el.com>
Subject: RE: [Intel-wired-lan] [PATCH iwl-net] idpf: fix null-ptr-deref in
 idpf_features_check



> -----Original Message-----
> From: Intel-wired-lan <intel-wired-lan-bounces@...osl.org> On Behalf Of
> Pavan Kumar Linga
> Sent: Friday, April 11, 2025 9:01 AM
> To: intel-wired-lan@...ts.osuosl.org
> Cc: netdev@...r.kernel.org; Linga, Pavan Kumar
> <pavan.kumar.linga@...el.com>; Chittim, Madhu
> <madhu.chittim@...el.com>
> Subject: [Intel-wired-lan] [PATCH iwl-net] idpf: fix null-ptr-deref in
> idpf_features_check
> 
> idpf_features_check is used to validate the TX packet. skb header length is
> compared with the hardware supported value received from the device
> control plane. The value is stored in the adapter structure and to access it,
> vport pointer is used. During reset all the vports are released and the vport
> pointer that the netdev private structure points to is NULL.
> 
> To avoid null-ptr-deref, store the max header length value in netdev private
> structure. This also helps to cache the value and avoid accessing adapter
> pointer in hot path.
> 
> BUG: kernel NULL pointer dereference, address: 0000000000000068 ...
> RIP: 0010:idpf_features_check+0x6d/0xe0 [idpf] Call Trace:
>  <TASK>
>  ? __die+0x23/0x70
>  ? page_fault_oops+0x154/0x520
>  ? exc_page_fault+0x76/0x190
>  ? asm_exc_page_fault+0x26/0x30
>  ? idpf_features_check+0x6d/0xe0 [idpf]
>  netif_skb_features+0x88/0x310
>  validate_xmit_skb+0x2a/0x2b0
>  validate_xmit_skb_list+0x4c/0x70
>  sch_direct_xmit+0x19d/0x3a0
>  __dev_queue_xmit+0xb74/0xe70
>  ...
> 
> Fixes: a251eee62133 ("idpf: add SRIOV support and other ndo_ops")
> Reviewed-by: Madhu Chititm <madhu.chittim@...el.com>
> Signed-off-by: Pavan Kumar Linga <pavan.kumar.linga@...el.com>
> ---
> 2.43.0

Tested-by: Samuel Salin <Samuel.salin@...el.com>

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ