From: Eugene Syromiatnikov Date: Sun, 12 Apr 2020 20:31:23 +0000 (+0200) Subject: clone3: add a check for the user struct size if CLONE_INTO_CGROUP is set X-Git-Tag: v5.7-rc2~15^2~1 X-Git-Url: http://git.ipfire.org/?a=commitdiff_plain;h=62173872ca65767c586217dec0a32485da8a2f07;p=thirdparty%2Fkernel%2Flinux.git clone3: add a check for the user struct size if CLONE_INTO_CGROUP is set Passing CLONE_INTO_CGROUP with an under-sized structure (that doesn't properly contain cgroup field) seems like garbage input, especially considering the fact that fd 0 is a valid descriptor. Signed-off-by: Eugene Syromiatnikov Acked-by: Christian Brauner Link: https://lore.kernel.org/r/20200412203123.GA5869@asgard.redhat.com Signed-off-by: Christian Brauner --- diff --git a/kernel/fork.c b/kernel/fork.c index b4f7775623c8d..3ab7cf88e4550 100644 --- a/kernel/fork.c +++ b/kernel/fork.c @@ -2631,7 +2631,8 @@ noinline static int copy_clone_args_from_user(struct kernel_clone_args *kargs, !valid_signal(args.exit_signal))) return -EINVAL; - if ((args.flags & CLONE_INTO_CGROUP) && args.cgroup > INT_MAX) + if ((args.flags & CLONE_INTO_CGROUP) && + (args.cgroup > INT_MAX || usize < CLONE_ARGS_SIZE_VER2)) return -EINVAL; *kargs = (struct kernel_clone_args){