diff options
author | Jason A. Donenfeld <Jason@zx2c4.com> | 2020-03-18 18:30:45 -0600 |
---|---|---|
committer | Jason A. Donenfeld <Jason@zx2c4.com> | 2022-07-07 13:26:41 +0200 |
commit | 94c5d5ba2ad2332167a912894788fa4f5d49d513 (patch) | |
tree | a7ccb617f75a78487031e9510f74230d01d6b4a1 /drivers/net/wireguard/noise.c | |
parent | 7f301e56b9033259a207288022ec1cf763bc7718 (diff) | |
download | wireguard-linux-trimmed-94c5d5ba2ad2332167a912894788fa4f5d49d513.tar.gz wireguard-linux-trimmed-94c5d5ba2ad2332167a912894788fa4f5d49d513.zip |
wireguard: queueing: account for skb->protocol==0
commit f0f7b639eb88ae0dd49b7f2e2979145a43c9e3ba upstream.
We carry out checks to the effect of:
if (skb->protocol != wg_examine_packet_protocol(skb))
goto err;
By having wg_skb_examine_untrusted_ip_hdr return 0 on failure, this
means that the check above still passes in the case where skb->protocol
is zero, which is possible to hit with AF_PACKET:
struct sockaddr_pkt saddr = { .spkt_device = "wg0" };
unsigned char buffer[5] = { 0 };
sendto(socket(AF_PACKET, SOCK_PACKET, /* skb->protocol = */ 0),
buffer, sizeof(buffer), 0, (const struct sockaddr *)&saddr, sizeof(saddr));
Additional checks mean that this isn't actually a problem in the code
base, but I could imagine it becoming a problem later if the function is
used more liberally.
I would prefer to fix this by having wg_examine_packet_protocol return a
32-bit ~0 value on failure, which will never match any value of
skb->protocol, which would simply change the generated code from a mov
to a movzx. However, sparse complains, and adding __force casts doesn't
seem like a good idea, so instead we just add a simple helper function
to check for the zero return value. Since wg_examine_packet_protocol
itself gets inlined, this winds up not adding an additional branch to
the generated code, since the 0 return value already happens in a
mergable branch.
Reported-by: Fabian Freyer <fabianfreyer@radicallyopensecurity.com>
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
Diffstat (limited to 'drivers/net/wireguard/noise.c')
0 files changed, 0 insertions, 0 deletions