Skip to content

Commit 44401f7

Browse files
r4uzngregkh
authored andcommitted
net: slip: serialize receive against buffer reallocation
commit ee7f9bb upstream. sl_realloc_bufs() replaces rbuff and updates buffsize while holding sl->lock. slip_receive_buf() reads those fields and writes through rbuff without holding the lock. An MTU change can therefore race with receive processing. An MTU shrink can expose the new smaller rbuff with the old larger bound, causing an out-of-bounds write. A receive callback which already loaded the old rbuff can instead continue writing after that buffer has been freed. Serialize receive processing with sl_realloc_bufs() by holding sl->lock while consuming each receive batch. Fixes: 1da177e ("Linux-2.6.12-rc2") Cc: stable@vger.kernel.org Signed-off-by: Sungmin Kang <726ksm@gmail.com> Link: https://patch.msgid.link/20260718073631.1674-1-726ksm@gmail.com Signed-off-by: Jakub Kicinski <kuba@kernel.org> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
1 parent 32d10c4 commit 44401f7

1 file changed

Lines changed: 4 additions & 0 deletions

File tree

drivers/net/slip/slip.c

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -693,6 +693,8 @@ static void slip_receive_buf(struct tty_struct *tty, const u8 *cp, const u8 *fp,
693693
if (!sl || sl->magic != SLIP_MAGIC || !netif_running(sl->dev))
694694
return;
695695

696+
spin_lock_bh(&sl->lock);
697+
696698
/* Read the characters out of the buffer */
697699
while (count--) {
698700
if (fp && *fp++) {
@@ -708,6 +710,8 @@ static void slip_receive_buf(struct tty_struct *tty, const u8 *cp, const u8 *fp,
708710
#endif
709711
slip_unesc(sl, *cp++);
710712
}
713+
714+
spin_unlock_bh(&sl->lock);
711715
}
712716

713717
/************************************

0 commit comments

Comments
 (0)