Commit 447a290e authored by Herbert Xu's avatar Herbert Xu Committed by Yongqiang Liu
Browse files

af_key: Fix send_acquire race with pfkey_register

stable inclusion
from stable-v4.19.268
commit 0c76cb8dcaf2561c7acef006af29ab9709fe001c
category: bugfix
bugzilla: https://gitee.com/openeuler/kernel/issues/I69KBO


CVE: NA

--------------------------------

[ Upstream commit 7f57f816 ]

The function pfkey_send_acquire may race with pfkey_register
(which could even be in a different name space).  This may result
in a buffer overrun.

Allocating the maximum amount of memory that could be used prevents
this.

Reported-by: default avatar <syzbot+1e9af9185d8850e2c2fa@syzkaller.appspotmail.com>
Fixes: 1da177e4 ("Linux-2.6.12-rc2")
Signed-off-by: default avatarHerbert Xu <herbert@gondor.apana.org.au>
Reviewed-by: default avatarSabrina Dubroca <sd@queasysnail.net>
Reviewed-by: default avatarEric Dumazet <edumazet@google.com>
Signed-off-by: default avatarSteffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: default avatarSasha Levin <sashal@kernel.org>
Signed-off-by: default avatarYongqiang Liu <liuyongqiang13@huawei.com>
parent c6ed8217
Loading
Loading
Loading
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please to comment