Linux kernel mirror (for testing) git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
kernel os linux

net: hsr: check skb can contain struct hsr_ethhdr in fill_frame_info

Check at start of fill_frame_info that the MAC header in the supplied
skb is large enough to fit a struct hsr_ethhdr, as otherwise this is
not a valid HSR frame. If it is too small, return an error which will
then cause the callers to clean up the skb. Fixes a KMSAN-found
uninit-value bug reported by syzbot at:
https://syzkaller.appspot.com/bug?id=f7e9b601f1414f814f7602a82b6619a8d80bce3f

Reported-by: syzbot+e267bed19bfc5478fb33@syzkaller.appspotmail.com
Signed-off-by: Phillip Potter <phil@philpotter.co.uk>
Signed-off-by: David S. Miller <davem@davemloft.net>

authored by

Phillip Potter and committed by
David S. Miller
2e9f6093 f282df03

+4
+4
net/hsr/hsr_forward.c
··· 520 520 struct ethhdr *ethhdr; 521 521 __be16 proto; 522 522 523 + /* Check if skb contains hsr_ethhdr */ 524 + if (skb->mac_len < sizeof(struct hsr_ethhdr)) 525 + return -EINVAL; 526 + 523 527 memset(frame, 0, sizeof(*frame)); 524 528 frame->is_supervision = is_supervision_frame(port->hsr, skb); 525 529 frame->node_src = hsr_get_node(port, &hsr->node_db, skb,