Linux kernel mirror (for testing) git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
kernel os linux

tcp: Fix sign comparison bug in getsockopt(TCP_ZEROCOPY_RECEIVE)

getsockopt(TCP_ZEROCOPY_RECEIVE) has a bug where we read a
user-provided "len" field of type signed int, and then compare the
value to the result of an "offsetofend" operation, which is unsigned.

Negative values provided by the user will be promoted to large
positive numbers; thus checking that len < offsetofend() will return
false when the intention was that it return true.

Note that while len is originally checked for negative values earlier
on in do_tcp_getsockopt(), subsequent calls to get_user() re-read the
value from userspace which may have changed in the meantime.

Therefore, re-add the check for negative values after the call to
get_user in the handler code for TCP_ZEROCOPY_RECEIVE.

Fixes: c8856c051454 ("tcp-zerocopy: Return inq along with tcp receive zerocopy.")
Reported-by: kernel test robot <lkp@intel.com>
Reported-by: Dan Carpenter <dan.carpenter@oracle.com>
Signed-off-by: Arjun Roy <arjunroy@google.com>
Link: https://lore.kernel.org/r/20210225232628.4033281-1-arjunroy.kdev@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>

authored by

Arjun Roy and committed by
Jakub Kicinski
2107d45f 6a4d7234

+2 -1
+2 -1
net/ipv4/tcp.c
··· 4143 4143 4144 4144 if (get_user(len, optlen)) 4145 4145 return -EFAULT; 4146 - if (len < offsetofend(struct tcp_zerocopy_receive, length)) 4146 + if (len < 0 || 4147 + len < offsetofend(struct tcp_zerocopy_receive, length)) 4147 4148 return -EINVAL; 4148 4149 if (unlikely(len > sizeof(zc))) { 4149 4150 err = check_zeroed_user(optval + sizeof(zc),