]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
net: slip: serialize receive against buffer reallocation
authorSungmin Kang <726ksm@gmail.com>
Sat, 18 Jul 2026 07:36:30 +0000 (16:36 +0900)
committerJakub Kicinski <kuba@kernel.org>
Thu, 23 Jul 2026 16:06:48 +0000 (09:06 -0700)
sl_realloc_bufs() replaces rbuff and updates buffsize while holding
sl->lock. slip_receive_buf() reads those fields and writes through rbuff
without holding the lock.

An MTU change can therefore race with receive processing. An MTU shrink
can expose the new smaller rbuff with the old larger bound, causing an
out-of-bounds write. A receive callback which already loaded the old
rbuff can instead continue writing after that buffer has been freed.

Serialize receive processing with sl_realloc_bufs() by holding sl->lock
while consuming each receive batch.

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Cc: stable@vger.kernel.org
Signed-off-by: Sungmin Kang <726ksm@gmail.com>
Link: https://patch.msgid.link/20260718073631.1674-1-726ksm@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
drivers/net/slip/slip.c

index 820e1a8fc9560ce265d06d857c1adb4b80fd554e..faae711cf793d3f2351f67dfaab6abb2d2b72b19 100644 (file)
@@ -693,6 +693,8 @@ static void slip_receive_buf(struct tty_struct *tty, const u8 *cp, const u8 *fp,
        if (!sl || sl->magic != SLIP_MAGIC || !netif_running(sl->dev))
                return;
 
+       spin_lock_bh(&sl->lock);
+
        /* Read the characters out of the buffer */
        while (count--) {
                if (fp && *fp++) {
@@ -708,6 +710,8 @@ static void slip_receive_buf(struct tty_struct *tty, const u8 *cp, const u8 *fp,
 #endif
                        slip_unesc(sl, *cp++);
        }
+
+       spin_unlock_bh(&sl->lock);
 }
 
 /************************************