mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/
synced 2026-09-28 19:20:30 +00:00
netfilter: nftables: exthdr: fix 4-byte stack OOB write
[ Upstream commitfd94d9dade] If priv->len is a multiple of 4, then dst[len / 4] can write past the destination array which leads to stack corruption. This construct is necessary to clean the remainder of the register in case ->len is NOT a multiple of the register size, so make it conditional just like nft_payload.c does. The bug was added in 4.1 cycle and then copied/inherited when tcp/sctp and ip option support was added. Bug reported by Zero Day Initiative project (ZDI-CAN-21950, ZDI-CAN-21951, ZDI-CAN-21961). Fixes:49499c3e6e("netfilter: nf_tables: switch registers to 32 bit addressing") Fixes:935b7f6430("netfilter: nft_exthdr: add TCP option matching") Fixes:133dc203d7("netfilter: nft_exthdr: Support SCTP chunks") Fixes:dbb5281a1f("netfilter: nf_tables: add support for matching IPv4 options") Signed-off-by: Florian Westphal <fw@strlen.de> Signed-off-by: Sasha Levin <sashal@kernel.org>
This commit is contained in:
parent
6cf0d1d5a5
commit
d9ebfc0f21
1 changed files with 14 additions and 8 deletions
Loading…
Add table
Add a link
Reference in a new issue