• Mark Salyzyn's avatar
    af_key: pfkey_dump needs parameter validation · 37bd2242
    Mark Salyzyn authored
    In pfkey_dump() dplen and splen can both be specified to access the
    xfrm_address_t structure out of bounds in__xfrm_state_filter_match()
    when it calls addr_match() with the indexes.  Return EINVAL if either
    are out of range.
    Signed-off-by: default avatarMark Salyzyn <salyzyn@android.com>
    Cc: netdev@vger.kernel.org
    Cc: linux-kernel@vger.kernel.org
    Cc: kernel-team@android.com
    Cc: Steffen Klassert <steffen.klassert@secunet.com>
    Cc: Herbert Xu <herbert@gondor.apana.org.au>
    Cc: "David S. Miller" <davem@davemloft.net>
    Cc: Jakub Kicinski <kuba@kernel.org>
    Fixes: 1da177e4 ("Linux-2.6.12-rc2")
    Signed-off-by: default avatarSteffen Klassert <steffen.klassert@secunet.com>
    37bd2242
af_key.c 101 KB