mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
synced 2026-09-22 09:34:56 +02:00
net: psample: fix info leak in PSAMPLE_ATTR_DATA
[ Upstream commitaedd02af1f] psample open codes nla_put() presumably to avoid wiping the data with 0s just to override it with packet data. This open coding is missing clearing the pad, however, each netlink attr is padded to 4B and data_len may not be divisible by 4B. Fixes:6ae0a62861("net: Introduce psample, a new genetlink channel for packet sampling") Reported-by: Weiming Shi <bestswngs@gmail.com> Reviewed-by: Jiri Pirko <jiri@nvidia.com> Link: https://patch.msgid.link/20260616003046.1099490-1-kuba@kernel.org Signed-off-by: Jakub Kicinski <kuba@kernel.org> Signed-off-by: Sasha Levin <sashal@kernel.org>
This commit is contained in:
committed by
Greg Kroah-Hartman
parent
19d2d36e19
commit
befe1ebe7f
@@ -465,15 +465,17 @@ void psample_sample_packet(struct psample_group *group, struct sk_buff *skb,
|
||||
goto error;
|
||||
|
||||
if (data_len) {
|
||||
int nla_len = nla_total_size(data_len);
|
||||
int nla_len = nla_attr_size(data_len);
|
||||
struct nlattr *nla;
|
||||
|
||||
nla = skb_put(nl_skb, nla_len);
|
||||
nla->nla_type = PSAMPLE_ATTR_DATA;
|
||||
nla->nla_len = nla_attr_size(data_len);
|
||||
nla->nla_len = nla_len;
|
||||
|
||||
if (skb_copy_bits(skb, 0, nla_data(nla), data_len))
|
||||
goto error;
|
||||
|
||||
skb_put_zero(nl_skb, nla_padlen(data_len));
|
||||
}
|
||||
|
||||
#ifdef CONFIG_INET
|
||||
|
||||
Reference in New Issue
Block a user