[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Qemu-devel] [PULL V2 12/12] net: check packet payload length
From: |
Jason Wang |
Subject: |
[Qemu-devel] [PULL V2 12/12] net: check packet payload length |
Date: |
Tue, 8 Mar 2016 15:52:44 +0800 |
From: Prasad J Pandit <address@hidden>
While computing IP checksum, 'net_checksum_calculate' reads
payload length from the packet. It could exceed the given 'data'
buffer size. Add a check to avoid it.
Reported-by: Liu Ling <address@hidden>
Signed-off-by: Prasad J Pandit <address@hidden>
Signed-off-by: Jason Wang <address@hidden>
---
net/checksum.c | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)
diff --git a/net/checksum.c b/net/checksum.c
index b5016ab..d0fa424 100644
--- a/net/checksum.c
+++ b/net/checksum.c
@@ -60,6 +60,11 @@ void net_checksum_calculate(uint8_t *data, int length)
int hlen, plen, proto, csum_offset;
uint16_t csum;
+ /* Ensure data has complete L2 & L3 headers. */
+ if (length < 14 + 20) {
+ return;
+ }
+
if ((data[14] & 0xf0) != 0x40)
return; /* not IPv4 */
hlen = (data[14] & 0x0f) * 4;
@@ -77,8 +82,9 @@ void net_checksum_calculate(uint8_t *data, int length)
return;
}
- if (plen < csum_offset+2)
- return;
+ if (plen < csum_offset + 2 || 14 + hlen + plen > length) {
+ return;
+ }
data[14+hlen+csum_offset] = 0;
data[14+hlen+csum_offset+1] = 0;
--
2.5.0
- [Qemu-devel] [PULL V2 02/12] net: filter: correctly remove filter from the list during finalization, (continued)
- [Qemu-devel] [PULL V2 02/12] net: filter: correctly remove filter from the list during finalization, Jason Wang, 2016/03/08
- [Qemu-devel] [PULL V2 03/12] MAINTAINERS: Add entries for include/net/ files, Jason Wang, 2016/03/08
- [Qemu-devel] [PULL V2 04/12] net: simplify net_init_tap_one logic, Jason Wang, 2016/03/08
- [Qemu-devel] [PULL V2 05/12] net: netmap: probe netmap interface for virtio-net header, Jason Wang, 2016/03/08
- [Qemu-devel] [PULL V2 06/12] rocker: forbid to change world type, Jason Wang, 2016/03/08
- [Qemu-devel] [PULL V2 07/12] rocker: return -ENOMEM in case of some world alloc fails, Jason Wang, 2016/03/08
- [Qemu-devel] [PULL V2 08/12] rocker: add name field into WorldOps ale let world specify its name, Jason Wang, 2016/03/08
- [Qemu-devel] [PULL V2 09/12] rocker: allow user to specify rocker world by property, Jason Wang, 2016/03/08
- [Qemu-devel] [PULL V2 10/12] filter: Add 'status' property for filter object, Jason Wang, 2016/03/08
- [Qemu-devel] [PULL V2 11/12] filter-buffer: Add status_changed callback processing, Jason Wang, 2016/03/08
- [Qemu-devel] [PULL V2 12/12] net: check packet payload length,
Jason Wang <=
- Re: [Qemu-devel] [PULL V2 00/12] Net patches, Peter Maydell, 2016/03/08