From: Mathias Krause Date: Wed, 19 Nov 2014 17:05:26 +0000 (+0100) Subject: pptp: fix stack info leak in pptp_getname() X-Git-Tag: v3.16.35~3528 X-Git-Url: http://git.ipfire.org/gitweb.cgi?a=commitdiff_plain;h=29065ee599be064881d09bc389f66f4d3e744a12;p=thirdparty%2Fkernel%2Fstable.git pptp: fix stack info leak in pptp_getname() commit a5f6fc28d6e6cc379c6839f21820e62262419584 upstream. pptp_getname() only partially initializes the stack variable sa, particularly only fills the pptp part of the sa_addr union. The code thereby discloses 16 bytes of kernel stack memory via getsockname(). Fix this by memset(0)'ing the union before. Cc: Dmitry Kozlov Signed-off-by: Mathias Krause Signed-off-by: David S. Miller Signed-off-by: Luis Henriques --- diff --git a/drivers/net/ppp/pptp.c b/drivers/net/ppp/pptp.c index 1aff970be33ec..1dc628ffce2b5 100644 --- a/drivers/net/ppp/pptp.c +++ b/drivers/net/ppp/pptp.c @@ -506,7 +506,9 @@ static int pptp_getname(struct socket *sock, struct sockaddr *uaddr, int len = sizeof(struct sockaddr_pppox); struct sockaddr_pppox sp; - sp.sa_family = AF_PPPOX; + memset(&sp.sa_addr, 0, sizeof(sp.sa_addr)); + + sp.sa_family = AF_PPPOX; sp.sa_protocol = PX_PROTO_PPTP; sp.sa_addr.pptp = pppox_sk(sock->sk)->proto.pptp.src_addr;