Arnaud Lecomte
aabc6596ff
net: ppp: Add bound checking for skb data on ppp_sync_txmung
Ensure we have enough data in linear buffer from skb before accessing
initial bytes. This prevents potential out-of-bounds accesses
when processing short packets.
When ppp_sync_txmung receives an incoming package with an empty
payload:
(remote) gef➤ p *(struct pppoe_hdr *) (skb->head + skb->network_header)
$18 = {
type = 0x1,
ver = 0x1,
code = 0x0,
sid = 0x2,
length = 0x0,
tag = 0xffff8880371cdb96
}
from the skb struct (trimmed)
tail = 0x16,
end = 0x140,
head = 0xffff88803346f400 "4",
data = 0xffff88803346f416 ":\377",
truesize = 0x380,
len = 0x0,
data_len = 0x0,
mac_len = 0xe,
hdr_len = 0x0,
it is not safe to access data[2].
Reported-by: syzbot+29fc8991b0ecb186cf40@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=29fc8991b0ecb186cf40
Tested-by: syzbot+29fc8991b0ecb186cf40@syzkaller.appspotmail.com
Fixes: 1da177e4c3 ("Linux-2.6.12-rc2")
Signed-off-by: Arnaud Lecomte <contact@arnaud-lcm.com>
Link: https://patch.msgid.link/20250408-bound-checking-ppp_txmung-v2-1-94bb6e1b92d0@arnaud-lcm.com
[pabeni@redhat.com: fixed subj typo]
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
2025-04-10 11:24:17 +02:00
..
2025-04-01 11:02:03 -07:00
2025-04-02 20:27:18 -07:00
2025-04-01 10:06:52 -07:00
2025-04-02 20:04:43 -07:00
2025-04-03 15:48:58 -07:00
2025-04-04 09:06:32 -07:00
2025-04-01 11:26:08 -07:00
2025-04-03 12:21:44 -07:00
2025-03-29 12:47:09 -07:00
2025-04-02 18:03:34 -07:00
2025-04-02 15:22:22 -07:00
2025-03-29 10:01:55 -07:00
2025-04-02 20:04:43 -07:00
2025-04-01 12:57:14 -07:00
2025-04-04 07:05:33 -07:00
2025-03-26 21:48:21 -07:00
2025-04-04 07:12:26 -07:00
2025-03-26 13:56:38 +01:00
2025-04-01 09:29:18 -07:00
2025-03-26 09:54:40 -07:00
2025-04-01 11:26:08 -07:00
2025-04-01 14:21:02 -07:00
2025-03-31 11:44:00 +02:00
2025-04-01 11:26:08 -07:00
2025-04-03 21:12:48 -07:00
2025-04-04 09:06:32 -07:00
2025-04-01 18:03:46 -07:00
2025-03-28 19:36:53 -07:00
2025-03-29 14:42:59 -07:00
2025-03-29 18:25:34 -07:00
2025-04-02 21:27:59 -07:00
2025-04-02 10:30:10 -07:00
2025-03-27 09:05:55 -07:00
2025-03-26 18:08:55 -07:00
2025-03-26 19:57:34 -07:00
2025-03-29 14:33:13 -07:00
2025-04-02 12:35:49 -07:00
2025-03-27 09:05:55 -07:00
2025-03-26 18:08:55 -07:00
2025-04-10 11:24:17 +02:00
2025-03-28 11:22:54 -07:00
2025-04-02 20:27:18 -07:00
2025-04-03 16:04:38 -07:00
2025-03-29 11:23:16 -07:00
2025-04-01 18:03:46 -07:00
2025-03-28 19:36:53 -07:00
2025-04-01 12:47:11 -07:00
2025-03-29 16:59:16 -07:00
2025-04-04 09:00:49 -07:00
2025-04-02 18:09:17 -07:00
2025-04-01 14:21:02 -07:00
2025-04-01 11:26:08 -07:00
2025-03-29 16:59:16 -07:00
2025-04-02 10:30:10 -07:00
2025-03-29 17:18:50 -07:00
2025-04-03 15:31:14 -07:00
2025-04-01 09:29:18 -07:00
2025-03-26 19:57:34 -07:00
2025-04-04 09:06:32 -07:00
2025-04-01 12:43:13 -07:00
2025-04-04 09:09:34 -07:00
2025-04-02 18:17:33 -07:00
2025-03-26 19:57:34 -07:00
2025-04-01 16:51:44 -07:00
2025-04-02 18:23:31 -07:00
2025-04-02 18:17:33 -07:00
2025-03-28 11:22:54 -07:00
2025-04-02 18:23:31 -07:00
2025-04-01 19:35:19 -07:00
2025-04-01 18:52:54 -07:00
2025-04-01 09:29:18 -07:00
2025-04-01 18:52:54 -07:00
2025-04-01 16:33:36 -07:00
2025-04-01 09:29:18 -07:00