diff options
author | Johannes Berg <johannes.berg@intel.com> | 2018-09-13 15:40:55 +0300 |
---|---|---|
committer | David S. Miller <davem@davemloft.net> | 2018-09-14 02:01:06 +0300 |
commit | 1cebf8f143c21eb422cd0f4e27ab2ae366eb4d04 (patch) | |
tree | 87b8677eb03c7a7faf5033ef1ee1b4576fcb9cb1 /lib | |
parent | c56cae23c6b167acc68043c683c4573b80cbcc2c (diff) | |
download | linux-1cebf8f143c21eb422cd0f4e27ab2ae366eb4d04.tar.xz |
socket: fix struct ifreq size in compat ioctl
As reported by Reobert O'Callahan, since Viro's commit to kill
dev_ifsioc() we attempt to copy too much data in compat mode,
which may lead to EFAULT when the 32-bit version of struct ifreq
sits at/near the end of a page boundary, and the next page isn't
mapped.
Fix this by passing the approprate compat/non-compat size to copy
and using that, as before the dev_ifsioc() removal. This works
because only the embedded "struct ifmap" has different size, and
this is only used in SIOCGIFMAP/SIOCSIFMAP which has a different
handler. All other parts of the union are naturally compatible.
This fixes https://bugzilla.kernel.org/show_bug.cgi?id=199469.
Fixes: bf4405737f9f ("kill dev_ifsioc()")
Reported-by: Robert O'Callahan <robert@ocallahan.org>
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Diffstat (limited to 'lib')
0 files changed, 0 insertions, 0 deletions