]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
rxgk: Fix potential integer overflow in length check
authorDavid Howells <dhowells@redhat.com>
Wed, 22 Apr 2026 16:14:34 +0000 (17:14 +0100)
committerJakub Kicinski <kuba@kernel.org>
Thu, 23 Apr 2026 19:40:52 +0000 (12:40 -0700)
Fix potential integer overflow in rxgk_extract_token() when checking the
length of the ticket.  Rather than rounding up the value to be tested
(which might overflow), round down the size of the available data.

Fixes: 2429a1976481 ("rxrpc: Fix untrusted unsigned subtract")
Closes: https://sashiko.dev/#/patchset/20260408121252.2249051-1-dhowells%40redhat.com
Signed-off-by: David Howells <dhowells@redhat.com>
cc: Marc Dionne <marc.dionne@auristor.com>
cc: Jeffrey Altman <jaltman@auristor.com>
cc: Simon Horman <horms@kernel.org>
cc: linux-afs@lists.infradead.org
cc: stable@kernel.org
Link: https://patch.msgid.link/20260422161438.2593376-6-dhowells@redhat.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
net/rxrpc/rxgk_app.c
net/rxrpc/rxgk_common.h

index 30275cb5ba3e25d8798272150ceef35fcbade7fe..5587639d60c5388874a0992653754fe438e56b7a 100644 (file)
@@ -214,7 +214,7 @@ int rxgk_extract_token(struct rxrpc_connection *conn, struct sk_buff *skb,
        ticket_len      = ntohl(container.token_len);
        ticket_offset   = token_offset + sizeof(container);
 
-       if (xdr_round_up(ticket_len) > token_len - sizeof(container))
+       if (ticket_len > xdr_round_down(token_len - sizeof(container)))
                goto short_packet;
 
        _debug("KVNO %u", kvno);
index 80164d89e19c03ea442d541f68404bf8d42fcc51..1e257d7ab8ec1b8ab7982a809c0c9a723c48cc44 100644 (file)
@@ -34,6 +34,7 @@ struct rxgk_context {
 };
 
 #define xdr_round_up(x) (round_up((x), sizeof(__be32)))
+#define xdr_round_down(x) (round_down((x), sizeof(__be32)))
 #define xdr_object_len(x) (4 + xdr_round_up(x))
 
 /*