Received: by 2002:a05:6a10:22f:0:0:0:0 with SMTP id 15csp424043pxk; Fri, 11 Sep 2020 10:29:26 -0700 (PDT) X-Google-Smtp-Source: ABdhPJxaca3HWaFvPbyXXtzFTRmtzdnsOFFvqeffSg7NXicTXlIGQWGqwFZEdnTgIkMC+OU+aioP X-Received: by 2002:a05:6402:156:: with SMTP id s22mr3242705edu.372.1599845366552; Fri, 11 Sep 2020 10:29:26 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1599845366; cv=none; d=google.com; s=arc-20160816; b=KVZI19L4ubY545xX7YVR595pSFXUgEBEteVumhYPXxsAvkDh7s32fkFMjXVetzb3KY j3w47rzB1ehWcMbGSMGKZoFX16l53TB0Ujb7WVILcV7y7hnbLaug184sYnwrkiI+GXOd eHK94w92dxg+YKpptKT9d8LGzjrxi1zuvEHj9Nqc/c6C44L+CdlM37U5Wi6jsOkEslNJ AsV2DXulVaP5zJoqKowBq4sRaf1m3XJqKNKEzT692osu7ZZJlzwUpvQsgthhWYSgL6vU iLAwjN52cHMRhbhpQyuWZe5KxuZ0dLWzMvcM/h4OlJ0eY+ipraf5iPkXbFrO/cPqIq+0 l34A== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:content-transfer-encoding:mime-version :user-agent:references:in-reply-to:message-id:date:subject:cc:to :from:dkim-signature; bh=Hn5d9+i4JJK6vCswjlMb/oQBf8TgTOkymJSKef++/y4=; b=TL+FpahFClz9qiphxVU2eWgPkOWnukfPWFWAdfou+hQp3LIpC8OwDJlEZB7EYVmGEp u/bDVmJD8cjfDeAV0uNaKgXZ2kwqdxQJ40EFqrjtgY+tj39EpPZqO4ML39a6Xnbn4YGU Db0GuCV7QHQzcSQA9xUZQxnoCPkIv54MDXtxLWADAzoFVPKMYR1bhMNL1ZTC2SymCYXB yVk9rKsYrmrHKMk/XBWemGkNQmg6cjG7v1imjcYkE6aarZll0RUF710Qj/05S3FafWwy Cmzj6WCDp3720Vd+W14yxKZv1+GBgZGblapLFLd9vMPDPwpw+kdjo4t1EZaaJq+wR28s 9ZjQ== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@kernel.org header.s=default header.b=MN2p2zbp; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=linuxfoundation.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id dm2si1647561ejc.334.2020.09.11.10.29.03; Fri, 11 Sep 2020 10:29:26 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=pass header.i=@kernel.org header.s=default header.b=MN2p2zbp; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=linuxfoundation.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1726440AbgIKR00 (ORCPT + 99 others); Fri, 11 Sep 2020 13:26:26 -0400 Received: from mail.kernel.org ([198.145.29.99]:49674 "EHLO mail.kernel.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1726027AbgIKM7I (ORCPT ); Fri, 11 Sep 2020 08:59:08 -0400 Received: from localhost (83-86-74-64.cable.dynamic.v4.ziggo.nl [83.86.74.64]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPSA id CE95722252; Fri, 11 Sep 2020 12:55:55 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=default; t=1599828956; bh=KM2ZCScpMhQmEqw3EHl70RAaPxWDQWDYdEhfpAG0ckI=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=MN2p2zbpbM8+GfYdJbQ++/cDmumIZnp49babU7xujoPRkoKr32WmdyOX82ShLW4BM Ccsf6wr374vrK8azu6ZzE3U+XYSsEmahGJKGULfRCzoSMoy8H/4OtDQFCKgAtJQMHo La8Htcovm7/AkMfoXXfvlWBS7ti7I9z1C6S2Ho2A= From: Greg Kroah-Hartman To: linux-kernel@vger.kernel.org Cc: Greg Kroah-Hartman , stable@vger.kernel.org, syzbot+ab16e463b903f5a37036@syzkaller.appspotmail.com, Sven Eckelmann , Antonio Quartulli , Simon Wunderlich , Sasha Levin Subject: [PATCH 4.9 10/71] batman-adv: Avoid uninitialized chaddr when handling DHCP Date: Fri, 11 Sep 2020 14:45:54 +0200 Message-Id: <20200911122505.456402555@linuxfoundation.org> X-Mailer: git-send-email 2.28.0 In-Reply-To: <20200911122504.928931589@linuxfoundation.org> References: <20200911122504.928931589@linuxfoundation.org> User-Agent: quilt/0.66 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org From: Sven Eckelmann [ Upstream commit 303216e76dcab6049c9d42390b1032f0649a8206 ] The gateway client code can try to optimize the delivery of DHCP packets to avoid broadcasting them through the whole mesh. But also transmissions to the client can be optimized by looking up the destination via the chaddr of the DHCP packet. But the chaddr is currently only done when chaddr is fully inside the non-paged area of the skbuff. Otherwise it will not be initialized and the unoptimized path should have been taken. But the implementation didn't handle this correctly. It didn't retrieve the correct chaddr but still tried to perform the TT lookup with this uninitialized memory. Reported-by: syzbot+ab16e463b903f5a37036@syzkaller.appspotmail.com Fixes: 6c413b1c22a2 ("batman-adv: send every DHCP packet as bat-unicast") Signed-off-by: Sven Eckelmann Acked-by: Antonio Quartulli Signed-off-by: Simon Wunderlich Signed-off-by: Sasha Levin --- net/batman-adv/gateway_client.c | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/net/batman-adv/gateway_client.c b/net/batman-adv/gateway_client.c index 3bd7ed6b6b3e1..9727afc030d8c 100644 --- a/net/batman-adv/gateway_client.c +++ b/net/batman-adv/gateway_client.c @@ -673,8 +673,10 @@ batadv_gw_dhcp_recipient_get(struct sk_buff *skb, unsigned int *header_len, chaddr_offset = *header_len + BATADV_DHCP_CHADDR_OFFSET; /* store the client address if the message is going to a client */ - if (ret == BATADV_DHCP_TO_CLIENT && - pskb_may_pull(skb, chaddr_offset + ETH_ALEN)) { + if (ret == BATADV_DHCP_TO_CLIENT) { + if (!pskb_may_pull(skb, chaddr_offset + ETH_ALEN)) + return BATADV_DHCP_NO; + /* check if the DHCP packet carries an Ethernet DHCP */ p = skb->data + *header_len + BATADV_DHCP_HTYPE_OFFSET; if (*p != BATADV_DHCP_HTYPE_ETHERNET) -- 2.25.1