Commit 94802151 authored by Steffen Klassert's avatar Steffen Klassert

Revert "xfrm: Fix stack-out-of-bounds read in xfrm_state_find."

This reverts commit c9f3f813.

This commit breaks transport mode when the policy template
has widlcard addresses configured, so revert it.
Signed-off-by: default avatarSteffen Klassert <steffen.klassert@secunet.com>
parent 0e74aa1d
...@@ -1362,29 +1362,36 @@ xfrm_tmpl_resolve_one(struct xfrm_policy *policy, const struct flowi *fl, ...@@ -1362,29 +1362,36 @@ xfrm_tmpl_resolve_one(struct xfrm_policy *policy, const struct flowi *fl,
struct net *net = xp_net(policy); struct net *net = xp_net(policy);
int nx; int nx;
int i, error; int i, error;
xfrm_address_t *daddr = xfrm_flowi_daddr(fl, family);
xfrm_address_t *saddr = xfrm_flowi_saddr(fl, family);
xfrm_address_t tmp; xfrm_address_t tmp;
for (nx = 0, i = 0; i < policy->xfrm_nr; i++) { for (nx = 0, i = 0; i < policy->xfrm_nr; i++) {
struct xfrm_state *x; struct xfrm_state *x;
xfrm_address_t *local; xfrm_address_t *remote = daddr;
xfrm_address_t *remote; xfrm_address_t *local = saddr;
struct xfrm_tmpl *tmpl = &policy->xfrm_vec[i]; struct xfrm_tmpl *tmpl = &policy->xfrm_vec[i];
remote = &tmpl->id.daddr; if (tmpl->mode == XFRM_MODE_TUNNEL ||
local = &tmpl->saddr; tmpl->mode == XFRM_MODE_BEET) {
if (xfrm_addr_any(local, tmpl->encap_family)) { remote = &tmpl->id.daddr;
error = xfrm_get_saddr(net, fl->flowi_oif, local = &tmpl->saddr;
&tmp, remote, if (xfrm_addr_any(local, tmpl->encap_family)) {
tmpl->encap_family, 0); error = xfrm_get_saddr(net, fl->flowi_oif,
if (error) &tmp, remote,
goto fail; tmpl->encap_family, 0);
local = &tmp; if (error)
goto fail;
local = &tmp;
}
} }
x = xfrm_state_find(remote, local, fl, tmpl, policy, &error, family); x = xfrm_state_find(remote, local, fl, tmpl, policy, &error, family);
if (x && x->km.state == XFRM_STATE_VALID) { if (x && x->km.state == XFRM_STATE_VALID) {
xfrm[nx++] = x; xfrm[nx++] = x;
daddr = remote;
saddr = local;
continue; continue;
} }
if (x) { if (x) {
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment