Re: [PATCH net] net/atm: fix slab-out-of-bounds read in vcc_setsockopt()

Eric Dumazet <[email protected]>
Newsgroups org.kernel.vger.netdev
Message-ID <CANn89iJrPf9BdQM3acoQB25YWBiSa9v8h_fJJMicBXZQG9LVag@mail.gmail.com>
On Tue, Aug 4, 2026 at 4:58 PM Eric Dumazet <[email protected]> wrote:
>
> vcc_setsockopt() never checked optlen for ATM-specific options (SO_ATMQOS
> and SO_SETCLP) and called copy_from_sockptr() assuming optval contained
> sufficient space for struct atm_qos or unsigned long.
>
> While copy_from_user() previously copied from a user buffer without checking
> optlen, the introduction of sockptr_t and cgroup BPF setsockopt filters allows
> optval to point to a kernel memory buffer allocated with a reduced optlen.
> Because copy_from_sockptr() on kernel pointers uses memcpy(), this leads to a
> KASAN slab-out-of-bounds read when optlen is smaller than the expected structure
> size.
>
> Fix this by using copy_safe_from_sockptr(), which validates that optlen is at
> least the expected size before copying.
>
> Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
> Reported-by: [email protected]
> Closes: https://lore.kernel.org/netdev/[email protected]/T/#u
> Signed-off-by: Eric Dumazet <[email protected]>
> ---
>  net/atm/common.c | 10 ++++++----
>  1 file changed, 6 insertions(+), 4 deletions(-)
>
> diff --git a/net/atm/common.c b/net/atm/common.c
> index c7f92405daf050ecd2a507e41efdd622ab8dc6a8..6a0c5184c0d6380deaa95f68cb97c7745b4f7b56 100644
> --- a/net/atm/common.c
> +++ b/net/atm/common.c
> @@ -722,8 +722,9 @@ int vcc_setsockopt(struct socket *sock, int level, int optname,
>         {
>                 struct atm_qos qos;
>
> -               if (copy_from_sockptr(&qos, optval, sizeof(qos)))
> -                       return -EFAULT;
> +               error = copy_safe_from_sockptr(&qos, sizeof(qos), optval, optlen);
> +               if (error)
> +                       return error;
>                 error = check_qos(&qos);
>                 if (error)
>                         return error;
> @@ -737,8 +738,9 @@ int vcc_setsockopt(struct socket *sock, int level, int optname,
>                 return 0;
>         }
>         case SO_SETCLP:
> -               if (copy_from_sockptr(&value, optval, sizeof(value)))
> -                       return -EFAULT;
> +               error = copy_safe_from_sockptr(&value, sizeof(value), optval, optlen);

I will send a V2, because @value is an "unsigned long", while a prior
check uses an "int"

#define SO_SETCLP   __SO_ENCODE(SOL_ATM,0,int)

I will change @value to an "int" in V2.

pw-bot: cr

> +               if (error)
> +                       return error;
>                 if (value)
>                         vcc->atm_options |= ATM_ATMOPT_CLP;
>                 else
> --
> 2.55.0.571.g244d577d93-goog
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.