Received: by 2002:a05:6358:3188:b0:123:57c1:9b43 with SMTP id q8csp399585rwd; Thu, 1 Jun 2023 01:38:57 -0700 (PDT) X-Google-Smtp-Source: ACHHUZ5wY3R/yIGR16lR5RncfcBaq8OBDFbXnhO150MZGMb7oTJFi5KEq5ESWe8P9hTpOI+TbKCY X-Received: by 2002:a92:d249:0:b0:33c:cb84:26d0 with SMTP id v9-20020a92d249000000b0033ccb8426d0mr2520034ilg.29.1685608737348; Thu, 01 Jun 2023 01:38:57 -0700 (PDT) ARC-Seal: i=2; a=rsa-sha256; t=1685608737; cv=pass; d=google.com; s=arc-20160816; b=X3xVg9zImissJosQFWsG2TsVk+VOOF3zu5U/fIN7qwJDlLHASy6x2XwuDRs2b5VYBd KZqPH59vurcmk8LOhCrS3aCQABI8JQPMI2QcY2fS0nWxffI7HPblj7+hG7YFyCZXCt3i 7WVQzm4qC5L84bp4Sr6wzZW3R4bQbnDj9M+5S/ha4Gguy1fx41PBlHLGipaven79GWS2 Ac3UtaTTSdJ1IUc855PZ4EjraE8k4MNVX+ROwjTTmdtu9W3sAh6brTijbmmFwAQvkpHY y2KxtzH4iN37Bmb01st4lmOp/8GXRB/lk8/oImK4cJKKUGJFKcGgZDeMKGQxI9ctbpDk nNkQ== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:mime-version:content-transfer-encoding :in-reply-to:from:content-language:references:cc:to:subject :user-agent:date:message-id:dkim-signature; bh=/oNEXTnaQvu65kPZkPeU6aotTYMudEjf3WeyB0s1NLs=; b=AKpTUUf16CARi5WKz3CT9uNvjEdwOpk/+3BtcLkkx3pfqH4sp3KLzw4Fg0aBqGy2pW cCssQmrPwefPTxPIomeVarkzwtutIM5PIMOBwP/A/gSIX0m8cfzURtB0BLXIn4Ypfyv0 JbvMnuPhR3n+XEGdPHFC4wZdwD01hyZf4G1hmIgV9js4c885tK3RUQ83DZ1ifXmCE1rV hJjgKC2rNF5zQYBTxyxMDAZ1K/4oI+QDgQIz1K/U/XfE/alM/m6+jNjB87BfIudJ+L69 IZIchk8j1RYa51BNs7vAS6KZlLKrfxNURop3wuyMOBFUuXylGoGPtL8wCxkayw5sj0fG xrTg== ARC-Authentication-Results: i=2; mx.google.com; dkim=pass header.i=@amd.com header.s=selector1 header.b=mDBQHQdO; arc=pass (i=1 spf=pass spfdomain=amd.com dkim=pass dkdomain=amd.com dmarc=pass fromdomain=amd.com); spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=amd.com Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id k21-20020a637b55000000b005348f85f89fsi2591370pgn.226.2023.06.01.01.38.42; Thu, 01 Jun 2023 01:38:57 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=pass header.i=@amd.com header.s=selector1 header.b=mDBQHQdO; arc=pass (i=1 spf=pass spfdomain=amd.com dkim=pass dkdomain=amd.com dmarc=pass fromdomain=amd.com); spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=amd.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S231840AbjFAIYX (ORCPT + 99 others); Thu, 1 Jun 2023 04:24:23 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:38196 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S231478AbjFAIYU (ORCPT ); Thu, 1 Jun 2023 04:24:20 -0400 Received: from NAM10-DM6-obe.outbound.protection.outlook.com (mail-dm6nam10on2050.outbound.protection.outlook.com [40.107.93.50]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 7F504E7; Thu, 1 Jun 2023 01:24:19 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=GKoY0S57tMp71VAVutufPQgxm0Clf9MjoSb1ei1/jAu04/DZXAMnickmh9jM77dYnBlIDkQtXvo/y72FlTpFUYR+p+RDdf9VJpUbxqTrwoaDfoIW6Wm4nxljgn3mpUSyiehEukm9pgEcbdOQ2VO0K/LRYecwzPhgtHFIh7o6/f0OGGC8W29+nslGo6eZbyl+SLR0KqqB7FTqAgXLgrUOc/jtgzTheAy2E8+NMWzHjDgKkSDUfQuxUmhOvrJ01dR/c1AW76urWmCC7nLYyj7Fsy25Gjb70wHxVKmm+EUhbJ8pvfGELmFrRmAOdAq/gwRoBX3d7K5EaDDbbtfaOGOs7w== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=/oNEXTnaQvu65kPZkPeU6aotTYMudEjf3WeyB0s1NLs=; b=Ap4MU3277IRdeiaixzEGX08b16N8/my4hkTpu0Vc325gj65r4gxrgIhL6xUk6LbQ30cb+Hq1QmEPVmt6kPJacPxz0ByGeoXgE4UBVbHeYaNqhTYzfCHG8WYWHEPxIogkCv/bcGrohvu2/X/hazGsEjMsg+fpCq1hQ6aaQuBaNikVMNEoyzaVX3lkG1HLg1jKNtr52wae7RNgV6Ox0oUGa6ZrEBSHw5rc6FBfq8b6kdrVCLaCl70VhTA5OyBWK59Qdm8K2FdllXXaZkMb7qzOjbaaC406RplUfqPjICSaCJOYpwvYkOMQFJwDM4BA0ujsrC3fT4T/D+9r1hxqIrxqiQ== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=amd.com; dmarc=pass action=none header.from=amd.com; dkim=pass header.d=amd.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=amd.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=/oNEXTnaQvu65kPZkPeU6aotTYMudEjf3WeyB0s1NLs=; b=mDBQHQdOi5o4+YkrVbipq6bcbbaPRTZhFxUhvhMI1wfgQx0Tb+C5erfwBjSAeOxq9w+Nje/ClDxJKzmorAW74hPrLu2zF8sWeax80OfB8AYMSkyztuAynXNFblkmr/zbVf3bPOBsvA08hV8E0hCyZunFLd8kncm21BCvSeM6KRM= Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=amd.com; Received: from DM8PR12MB5398.namprd12.prod.outlook.com (2603:10b6:8:3f::5) by BN9PR12MB5273.namprd12.prod.outlook.com (2603:10b6:408:11e::22) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6455.23; Thu, 1 Jun 2023 08:24:16 +0000 Received: from DM8PR12MB5398.namprd12.prod.outlook.com ([fe80::c80a:17d6:8308:838]) by DM8PR12MB5398.namprd12.prod.outlook.com ([fe80::c80a:17d6:8308:838%4]) with mapi id 15.20.6433.022; Thu, 1 Jun 2023 08:24:16 +0000 Message-ID: Date: Thu, 1 Jun 2023 09:24:10 +0100 User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:102.0) Gecko/20100101 Thunderbird/102.11.0 Subject: Re: [PATCH net v2] net/sched: flower: fix possible OOB write in fl_set_geneve_opt() To: Hangyu Hua , jhs@mojatatu.com, xiyou.wangcong@gmail.com, jiri@resnulli.us, davem@davemloft.net, edumazet@google.com, kuba@kernel.org, pabeni@redhat.com, simon.horman@corigine.com Cc: netdev@vger.kernel.org, linux-kernel@vger.kernel.org References: <20230531102805.27090-1-hbh25y@gmail.com> Content-Language: en-US From: Pieter Jansen van Vuuren In-Reply-To: <20230531102805.27090-1-hbh25y@gmail.com> Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit X-ClientProxiedBy: LO4P265CA0289.GBRP265.PROD.OUTLOOK.COM (2603:10a6:600:38f::12) To DM8PR12MB5398.namprd12.prod.outlook.com (2603:10b6:8:3f::5) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: DM8PR12MB5398:EE_|BN9PR12MB5273:EE_ X-MS-Office365-Filtering-Correlation-Id: 03e45cae-1885-45b0-6e06-08db62799691 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0; X-Microsoft-Antispam-Message-Info: t3Hgrpen+HL+dcF5AFZdVYPQ3ggTraqcipYJrSpNrkKyJbqUS79Ej9BbJjiROqI0KjF7JMwUtHav6gW4J00zV7mLJUiasoQ8rv6ivW6GF19u9ohgXskC5Rg3D1rsow3F3xGJYK17ImmF3fpU3/m9aeS0osfrnBXQaTw2O0DyweiqsEak6r6mme/p6bLvBPyf40sq2IXHWz04ixCNyKv1xn6NrsuAyurZ4WWWBd4LeObUR+zc4sjDQPYUE39bncafUfCr56BX8Jh5KxHuS8U+A5jxVfOcg6Apkiitn8CX9aYVj02D2Q4BbHoNcFASKQwUu2ua2mpOQdgMqhAp4wDBeJ87wZOOJzdIa1nRRvaJYm9WUFgHjz86BM8Nvg7U8uTz1xbeFZfJTd/7cNnzlO6l4cMoszDbJxWWBNFYFPmWIcxGFPRUWp2Izl9poW2R8ccVaLgjAInuLQysV6vK35S9iMoUgT7AwtkIQSSaowdNQh0zNUI7qdGH9bEHnsWJvGhjGlzOMuQH4UDix+o6CIJvvsIDqXXeTJSeK6OGXYwKCAUCBymNcAqsqgnCyCeXCf1Ziw2yi4k8cx1bmTBWstj68/aNwCJhfRVyAVEny3huQ/7GtZDgDP/Xp6OFUsYNZNoZGIRy7CB02Y7VjY3Q0gTHzA== X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DM8PR12MB5398.namprd12.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230028)(4636009)(39860400002)(346002)(396003)(376002)(366004)(136003)(451199021)(36756003)(38100700002)(86362001)(31696002)(31686004)(8936002)(8676002)(41300700001)(7416002)(5660300002)(26005)(6512007)(53546011)(6506007)(4744005)(2906002)(186003)(2616005)(6666004)(316002)(66556008)(66476007)(66946007)(6486002)(478600001)(4326008)(43740500002)(45980500001);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: =?utf-8?B?MjFJM2xmYWpOK0pDb0RhSVR2MFBXY0ZDelc5ZEgreC9xb3gzNHU0THQvT1Nw?= =?utf-8?B?ZU5ZWEFOemwvSEE2OFdhNXgzSXUrVGNCenlocDd0Rmdtc1VsUmFIUlhERkN4?= =?utf-8?B?Tnl4aENOZnAxZHNSTHRkSnY0ZUNYQ09nSUJBM2NRamZ4QXhZWnlndUZ2N0xl?= =?utf-8?B?cW5vbzNvcXhqazRrQkUzRGthZkVaVXdMeDBrN3BGeVVXQUdxd2xpWnZWb2g1?= =?utf-8?B?aVIwdmNJbzlKeUxYQVh1akcrVVpHQkx4NXI0b0RoL0NTdGJRY3BsNUhjVVBw?= =?utf-8?B?bkJCalFlWDZrSDNkeVF1WG1qYVQ1MVBsTWthQ1RQZVFwWWJGWnBQbGlIUzNJ?= =?utf-8?B?WTdlbnVDS3VtWXpVL0FXME9WektXcnpmY200WkhuNlZwY2lJbHhLKyt2UDJK?= =?utf-8?B?WmgySkNKbE95Qk9KU3QrU2VSTDA2WmRwam1YSHdQY1VCbGlEc1daNVRkODNj?= =?utf-8?B?YXR5bWJZQkVabGRXRCsrZ3U1K2dmbmF6NDVrMEYySEgyQ2I1dkVLbGlFN080?= =?utf-8?B?eFNiWE9BdW8zaTRvcmY2NzQ0SnhSWmxxeENOSXlNY0E0Yk1XNldzbTVEV0Jh?= =?utf-8?B?M3drZ3ZTUGdzT0txYXY5MWR5QlVVQTNyYllTQnRyZDA4Q2FhcWVaZjhHbllX?= =?utf-8?B?RHBMNzc4dElla0paTVd1dkJLTHFESnVSQ00wSlVwNmNlM0Iyb1ZRaXhpc0Qw?= =?utf-8?B?RndCN1kvZ3NkMFNDd1MydHAzMlVLYzhjVi9DakVEQVBnWllLMUZVVnVtT3A0?= =?utf-8?B?VHo2SDk0dTMzTEFmOVV1R0l2WDhjaXJrbjNjU2RKTzR3OTROL2lPK2NWLzBl?= =?utf-8?B?QmI1TFhNYUJHNWorSE9hNFJYTWpUeDBVT1JzR0pHczRvbk02S0dGMjltcWNt?= =?utf-8?B?Y2F6TDAwL2RoNjZKMFhiSzY0YzUrb2Vlb1VodzNGazRLZFVjZlhubmM0aTBZ?= =?utf-8?B?Vm9tajMvUWFpdzZYUjRMREVveVlUd2F0dUNUSXQ1SkxzUDlPK2hBNk42Rkdu?= =?utf-8?B?SXQ3ZjRQRXRSRTlSaTVGZ3BjQkVmUGU1R0NHa0pqSDNoSjFMMnAvRVZnbDlz?= =?utf-8?B?ZmQ4TUdhTlI3anhScEl0OUJRSWUxMjRYNkJHenVxWEtoUThEa29VdVNyaWZ0?= =?utf-8?B?VzZxUjM1TlgwZWgyUDNQSUkzNFBSZzMxM2xpRmdubDhTM2R4UTNPRXVJeVJl?= =?utf-8?B?MnY2R3kxWmptYzV6TXlGVUhlSWlBUmdtQU9Jb2dKelU1Mk9yWkwwVFlJRUIw?= =?utf-8?B?QUpIWUhkZlFTUEVVV1lEbG90WE5PcjdhMCtIemczNXl3QXh0YmxKVHlRa3k4?= =?utf-8?B?R0trRHp6WEFHeFdKdFpocENjbExqamJzSkpnU2NOWTVWeEFwb3J0S2F0NU51?= =?utf-8?B?NGVLRDVCZG8yVE9ORlVGbUg2NjhaNHZnSlNTcGFqV01jK204QjNWbjlhYXg4?= =?utf-8?B?bVpjd1dlODFvOTlHTFA5b0dUcWE4b1U0MlRCWjBoRFUrRDhmKzBCSHFmNjNJ?= =?utf-8?B?WW91Q1h3QXkvTzRRbWo5VTJWdk1udEtTWjhPa3crb0RLL2d5Qk1WRXp0c2Q0?= =?utf-8?B?blk4ZWtzc2g0MjRpV0pwMHNFTWMzVndGODFFRjM3TzdCUmMzZXZaYk82Z3lK?= =?utf-8?B?ZFNCelRhVUtLSVp0RXFZVW14SzVoeXBQdENVT2ovY2JSNUJQanlYbkFnbmt6?= =?utf-8?B?cHVqYWpMU2dvQzV0N0dPYS9uMnlZb3dydzVEWnJEdFl2NkljYllKVVloMXRB?= =?utf-8?B?dy90K2k2dkUzK3BscHZ5VFVOd3h1VVRqa1JhSlQ2RlI0ampuTjk4elpDbFNN?= =?utf-8?B?WTJkVFJIV04yV3pvc3ZDMXd3Y0gwOFZUT3J3OTRHK0Y5YVBpa1lHaDRzdldZ?= =?utf-8?B?TGhsbzNwVS93Wk5laGVYYTlhWW5aaHVvTTRiVVNIY29WVG83M2ZWTDVKVnJo?= =?utf-8?B?aUZiK1krTzZiMFU3RllzZmlNd2tDQllEaCt3ekV4SHlOYjI2Mlo3M05iY3Z5?= =?utf-8?B?NFp5TCtMRGx0Y0ROVTdvVDN4NkFYcVVOOEpuWXdMaU9XUlBCQ3pGdVRpTWt3?= =?utf-8?B?R29DTEpCMVpDUCtNeTJMMThLVWxCdHRDNjh0OWNsMTZ5SXJ1bjg0akFLZDIy?= =?utf-8?Q?9MtouMITwU5BvH0N/rtQyRYD0?= X-OriginatorOrg: amd.com X-MS-Exchange-CrossTenant-Network-Message-Id: 03e45cae-1885-45b0-6e06-08db62799691 X-MS-Exchange-CrossTenant-AuthSource: DM8PR12MB5398.namprd12.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 01 Jun 2023 08:24:16.2970 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 3dd8961f-e488-4e60-8e11-a82d994e183d X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: 3iH0gXKEMDt899MnnFeojXp25I4KLRsAYONZ6uF/9oe5g2T/UxbJqAMfYHgqXDPx X-MS-Exchange-Transport-CrossTenantHeadersStamped: BN9PR12MB5273 X-Spam-Status: No, score=-1.2 required=5.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,FORGED_SPF_HELO,NICE_REPLY_A, RCVD_IN_DNSWL_NONE,RCVD_IN_MSPIKE_H2,SPF_HELO_PASS,SPF_NONE, T_SCC_BODY_TEXT_LINE autolearn=no autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On 31/05/2023 11:28, Hangyu Hua wrote: > If we send two TCA_FLOWER_KEY_ENC_OPTS_GENEVE packets and their total > size is 252 bytes(key->enc_opts.len = 252) then > key->enc_opts.len = opt->length = data_len / 4 = 0 when the third > TCA_FLOWER_KEY_ENC_OPTS_GENEVE packet enters fl_set_geneve_opt. This > bypasses the next bounds check and results in an out-of-bounds. > > Fixes: 0a6e77784f49 ("net/sched: allow flower to match tunnel options") > Signed-off-by: Hangyu Hua Reviewed-by: Pieter Jansen van Vuuren