summaryrefslogtreecommitdiff
path: root/crypto/ecdh.c
diff options
context:
space:
mode:
authorEric Biggers <ebiggers@google.com>2020-10-26 13:07:15 -0700
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>2020-12-30 11:51:00 +0100
commitf5e56bcaa4129333f8ecd065d94ecae510aa1da2 (patch)
tree971750cdd70e265a08a367c97fb575df235c3bb3 /crypto/ecdh.c
parent0e5eeecbb71d353bd2975f56121c1261c103021d (diff)
downloadlinux-crypto-f5e56bcaa4129333f8ecd065d94ecae510aa1da2.tar.gz
linux-crypto-f5e56bcaa4129333f8ecd065d94ecae510aa1da2.zip
crypto: af_alg - avoid undefined behavior accessing salg_name
commit e1cbfc28701813b40fe3891526dfc55f475bae8d upstream. Commit 7175dac1d936 ("crypto: af_alg - Allow arbitrarily long algorithm names") made the kernel start accepting arbitrarily long algorithm names in sockaddr_alg. However, the actual length of the salg_name field stayed at the original 64 bytes. This is broken because the kernel can access indices >= 64 in salg_name, which is undefined behavior -- even though the memory that is accessed is still located within the sockaddr structure. It would only be defined behavior if the array were properly marked as arbitrary-length (either by making it a flexible array, which is the recommended way these days, or by making it an array of length 0 or 1). We can't simply change salg_name into a flexible array, since that would break source compatibility with userspace programs that embed sockaddr_alg into another struct, or (more commonly) declare a sockaddr_alg like 'struct sockaddr_alg sa = { .salg_name = "foo" };'. One solution would be to change salg_name into a flexible array only when '#ifdef __KERNEL__'. However, that would keep userspace without an easy way to actually use the longer algorithm names. Instead, add a new structure 'sockaddr_alg_new' that has the flexible array field, and expose it to both userspace and the kernel. Make the kernel use it correctly in alg_bind(). This addresses the syzbot report "UBSAN: array-index-out-of-bounds in alg_bind" (https://syzkaller.appspot.com/bug?extid=92ead4eb8e26a26d465e). Reported-by: syzbot+92ead4eb8e26a26d465e@syzkaller.appspotmail.com Fixes: 7175dac1d936 ("crypto: af_alg - Allow arbitrarily long algorithm names") Cc: <stable@vger.kernel.org> # v4.12+ Signed-off-by: Eric Biggers <ebiggers@google.com> Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Diffstat (limited to 'crypto/ecdh.c')
0 files changed, 0 insertions, 0 deletions