From: Thomas Graf Date: Wed, 15 Feb 2012 04:09:46 +0000 (+0000) Subject: veth: Enforce minimum size of VETH_INFO_PEER X-Git-Tag: firefly_0821_release~7541^2~1720 X-Git-Url: http://demsky.eecs.uci.edu/git/?a=commitdiff_plain;h=497f51fc64d0bce7f1a40ebed20b2ba5090777a3;p=firefly-linux-kernel-4.4.55.git veth: Enforce minimum size of VETH_INFO_PEER [ Upstream commit 237114384ab22c174ec4641e809f8e6cbcfce774 ] VETH_INFO_PEER carries struct ifinfomsg plus optional IFLA attributes. A minimal size of sizeof(struct ifinfomsg) must be enforced or we may risk accessing that struct beyond the limits of the netlink message. Signed-off-by: Thomas Graf Signed-off-by: David S. Miller Signed-off-by: Greg Kroah-Hartman --- diff --git a/drivers/net/veth.c b/drivers/net/veth.c index 4bf7c6d4ab90..6c0a3b0f0afd 100644 --- a/drivers/net/veth.c +++ b/drivers/net/veth.c @@ -421,7 +421,9 @@ static void veth_dellink(struct net_device *dev, struct list_head *head) unregister_netdevice_queue(peer, head); } -static const struct nla_policy veth_policy[VETH_INFO_MAX + 1]; +static const struct nla_policy veth_policy[VETH_INFO_MAX + 1] = { + [VETH_INFO_PEER] = { .len = sizeof(struct ifinfomsg) }, +}; static struct rtnl_link_ops veth_link_ops = { .kind = DRV_NAME,