]> git.ipfire.org Git - thirdparty/kernel/stable.git/commit
netlabel: fix out-of-bounds memory accesses
authorPaul Moore <paul@paul-moore.com>
Tue, 26 Feb 2019 00:06:06 +0000 (19:06 -0500)
committerBen Hutchings <ben@decadent.org.uk>
Thu, 2 May 2019 20:42:01 +0000 (21:42 +0100)
commit97bc3683c24999ee621d847c9348c75d2fe86272
treef191c7b579dccb173f694d3e8628310e4805e347
parentc90030281dc8b6a25ac8850e98e15877f80b8d66
netlabel: fix out-of-bounds memory accesses

commit 5578de4834fe0f2a34fedc7374be691443396d1f upstream.

There are two array out-of-bounds memory accesses, one in
cipso_v4_map_lvl_valid(), the other in netlbl_bitmap_walk().  Both
errors are embarassingly simple, and the fixes are straightforward.

As a FYI for anyone backporting this patch to kernels prior to v4.8,
you'll want to apply the netlbl_bitmap_walk() patch to
cipso_v4_bitmap_walk() as netlbl_bitmap_walk() doesn't exist before
Linux v4.8.

Reported-by: Jann Horn <jannh@google.com>
Fixes: 446fda4f2682 ("[NetLabel]: CIPSOv4 engine")
Fixes: 3faa8f982f95 ("netlabel: Move bitmap manipulation functions to the NetLabel core.")
Signed-off-by: Paul Moore <paul@paul-moore.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
[bwh: Backported to 3.16 following Paul's hint]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
net/ipv4/cipso_ipv4.c