Re: [PATCH v2 net 2/2] ppp, slip: Validate VJ compression slot parameters completely

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



From: Ben Hutchings <ben@xxxxxxxxxxxxxxx>
Date: Sun, 1 Nov 2015 16:22:53 +0000

> Currently slhc_init() treats out-of-range values of rslots and tslots
> as equivalent to 0, except that if tslots is too large it will
> dereference a null pointer (CVE-2015-7799).
> 
> Add a range-check at the top of the function and make it return an
> ERR_PTR() on error instead of NULL.  Change the callers accordingly.
> 
> Compile-tested only.
> 
> Reported-by: 郭永刚 <guoyonggang@xxxxxx>
> References: http://article.gmane.org/gmane.comp.security.oss.general/17908
> Signed-off-by: Ben Hutchings <ben@xxxxxxxxxxxxxxx>

Applied.
��.n��������+%������w��{.n�����{���i�)��jg��������ݢj����G�������j:+v���w�m������w�������h�����٥




[Index of Archives]     [Linux Audio Users]     [Linux for Hams]     [Kernel Newbies]     [Security]     [Netfilter]     [Bugtraq]     [Yosemite News]     [MIPS Linux]     [ARM Linux]     [Linux Security]     [Linux RAID]     [Samba]     [Video 4 Linux]     [Fedora Users]

  Powered by Linux