Re: [PATCH net] net/atm: fix slab-out-of-bounds read in vcc_setsockopt()
Eric Dumazet <[email protected]>
| Newsgroups | org.kernel.vger.netdev |
|---|---|
| Message-ID | <CANn89iJrPf9BdQM3acoQB25YWBiSa9v8h_fJJMicBXZQG9LVag@mail.gmail.com> |
On Tue, Aug 4, 2026 at 4:58 PM Eric Dumazet <[email protected]> wrote: > > vcc_setsockopt() never checked optlen for ATM-specific options (SO_ATMQOS > and SO_SETCLP) and called copy_from_sockptr() assuming optval contained > sufficient space for struct atm_qos or unsigned long. > > While copy_from_user() previously copied from a user buffer without checking > optlen, the introduction of sockptr_t and cgroup BPF setsockopt filters allows > optval to point to a kernel memory buffer allocated with a reduced optlen. > Because copy_from_sockptr() on kernel pointers uses memcpy(), this leads to a > KASAN slab-out-of-bounds read when optlen is smaller than the expected structure > size. > > Fix this by using copy_safe_from_sockptr(), which validates that optlen is at > least the expected size before copying. > > Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") > Reported-by: [email protected] > Closes: https://lore.kernel.org/netdev/[email protected]/T/#u > Signed-off-by: Eric Dumazet <[email protected]> > --- > net/atm/common.c | 10 ++++++---- > 1 file changed, 6 insertions(+), 4 deletions(-) > > diff --git a/net/atm/common.c b/net/atm/common.c > index c7f92405daf050ecd2a507e41efdd622ab8dc6a8..6a0c5184c0d6380deaa95f68cb97c7745b4f7b56 100644 > --- a/net/atm/common.c > +++ b/net/atm/common.c > @@ -722,8 +722,9 @@ int vcc_setsockopt(struct socket *sock, int level, int optname, > { > struct atm_qos qos; > > - if (copy_from_sockptr(&qos, optval, sizeof(qos))) > - return -EFAULT; > + error = copy_safe_from_sockptr(&qos, sizeof(qos), optval, optlen); > + if (error) > + return error; > error = check_qos(&qos); > if (error) > return error; > @@ -737,8 +738,9 @@ int vcc_setsockopt(struct socket *sock, int level, int optname, > return 0; > } > case SO_SETCLP: > - if (copy_from_sockptr(&value, optval, sizeof(value))) > - return -EFAULT; > + error = copy_safe_from_sockptr(&value, sizeof(value), optval, optlen); I will send a V2, because @value is an "unsigned long", while a prior check uses an "int" #define SO_SETCLP __SO_ENCODE(SOL_ATM,0,int) I will change @value to an "int" in V2. pw-bot: cr > + if (error) > + return error; > if (value) > vcc->atm_options |= ATM_ATMOPT_CLP; > else > -- > 2.55.0.571.g244d577d93-goog >