Please sign in to comment.
netfilter: ebtables: CONFIG_COMPAT: don't trust userland offsets
We need to make sure the offsets are not out of range of the total size. Also check that they are in ascending order. The WARN_ON triggered by syzkaller (it sets panic_on_warn) is changed to also bail out, no point in continuing parsing. Briefly tested with simple ruleset of -A INPUT --limit 1/s' --log plus jump to custom chains using 32bit ebtables binary. Reported-by: <email@example.com> Signed-off-by: Florian Westphal <firstname.lastname@example.org> Signed-off-by: Pablo Neira Ayuso <email@example.com>
- Loading branch information...