]> git.ipfire.org Git - thirdparty/u-boot.git/commitdiff
net: ipv6: router advertisement message length should be within limits
authorEhsan Mohandesi <emohandesi@linux.microsoft.com>
Thu, 18 May 2023 18:24:38 +0000 (11:24 -0700)
committerTom Rini <trini@konsulko.com>
Thu, 27 Jul 2023 17:39:07 +0000 (13:39 -0400)
The argument len passed to function process_ra is the length of the IPv6
router advertisement message and needs to be between 0 and MTU because
it is assigned to remaining_option_len and used as a loop variable.

Addresses-Coverity-ID: 450971 ("TAINTED_SCALAR")
Signed-off-by: Ehsan Mohandesi <emohandesi@linux.microsoft.com>
Reviewed-by: Viacheslav Mitrofanov <v.v.mitrofanov@yadro.com>
Reviewed-by: Ramon Fried <rfried.dev@gmail.com>
net/ndisc.c

index 0b27779ce5ac060d19366a83a1c57cc133cc62bb..d1cec0601c83ea10961f50bcc344399e0a3caa3b 100644 (file)
@@ -382,6 +382,8 @@ int process_ra(struct ip6_hdr *ip6, int len)
        unsigned char type = 0;
        struct icmp6_ra_prefix_info *prefix = NULL;
 
+       if (len > ETH_MAX_MTU)
+               return -EMSGSIZE;
        /* Ignore the packet if router lifetime is 0. */
        if (!icmp->icmp6_rt_lifetime)
                return -EOPNOTSUPP;