Skip to content

Commit 7d0a065

Browse files
kcp-gitdavem330
authored andcommitted
net/rds: Fix info leak in rds6_inc_info_copy()
The rds6_inc_info_copy() function has a couple struct members which are leaking stack information. The ->tos field should hold actual information and the ->flags field needs to be zeroed out. Fixes: 3eb4503 ("rds: add type of service(tos) infrastructure") Fixes: b7ff8b1 ("rds: Extend RDS API for IPv6 support") Reported-by: 黄ID蝴蝶 <butterflyhuangxx@gmail.com> Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com> Signed-off-by: Ka-Cheong Poon <ka-cheong.poon@oracle.com> Acked-by: Santosh Shilimkar <santosh.shilimkar@oracle.com> Signed-off-by: David S. Miller <davem@davemloft.net>
1 parent 2c1644c commit 7d0a065

File tree

1 file changed

+4
-1
lines changed

1 file changed

+4
-1
lines changed

Diff for: net/rds/recv.c

+4-1
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
/*
2-
* Copyright (c) 2006, 2018 Oracle and/or its affiliates. All rights reserved.
2+
* Copyright (c) 2006, 2019 Oracle and/or its affiliates. All rights reserved.
33
*
44
* This software is available to you under a choice of one of two
55
* licenses. You may choose to be licensed under the terms of the GNU
@@ -811,6 +811,7 @@ void rds6_inc_info_copy(struct rds_incoming *inc,
811811

812812
minfo6.seq = be64_to_cpu(inc->i_hdr.h_sequence);
813813
minfo6.len = be32_to_cpu(inc->i_hdr.h_len);
814+
minfo6.tos = inc->i_conn->c_tos;
814815

815816
if (flip) {
816817
minfo6.laddr = *daddr;
@@ -824,6 +825,8 @@ void rds6_inc_info_copy(struct rds_incoming *inc,
824825
minfo6.fport = inc->i_hdr.h_dport;
825826
}
826827

828+
minfo6.flags = 0;
829+
827830
rds_info_copy(iter, &minfo6, sizeof(minfo6));
828831
}
829832
#endif

0 commit comments

Comments
 (0)