diff options
author | M A Ramdhan <ramdhan@starlabs.sg> | 2023-07-05 12:15:30 -0400 |
---|---|---|
committer | Pindar Yang <pindaryang@google.com> | 2023-09-07 05:43:03 +0000 |
commit | 7b0944645172e8b690d42f68c8973ccb0ca45730 (patch) | |
tree | 590052e86eca5409d468adc8e4d15181acb5b856 | |
parent | 1f0f7f32382465b374864ad5b0fb2c02ceb3ba07 (diff) | |
download | msm-android-msm-redbull-4.19-android14.tar.gz |
UPSTREAM: net/sched: cls_fw: Fix improper refcount update leads to use-after-freeandroid-14.0.0_r0.47android-14.0.0_r0.12android-msm-redbull-4.19-android14-releaseandroid-msm-redbull-4.19-android14
[ Upstream commit 0323bce598eea038714f941ce2b22541c46d488f ]
In the event of a failure in tcf_change_indev(), fw_set_parms() will
immediately return an error after incrementing or decrementing
reference counter in tcf_bind_filter(). If attacker can control
reference counter to zero and make reference freed, leading to
use after free.
In order to prevent this, move the point of possible failure above the
point where the TC_FW_CLASSID is handled.
Bug: 292252062
Bug: 290783303
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Reported-by: M A Ramdhan <ramdhan@starlabs.sg>
Signed-off-by: M A Ramdhan <ramdhan@starlabs.sg>
Acked-by: Jamal Hadi Salim <jhs@mojatatu.com>
Reviewed-by: Pedro Tammela <pctammela@mojatatu.com>
Message-ID: <20230705161530.52003-1-ramdhan@starlabs.sg>
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
(cherry picked from commit c91fb29bb07ee4dd40aabd1e41f19c0f92ac3199)
Signed-off-by: Lee Jones <joneslee@google.com>
(cherry picked from commit a89c7b9715e2d482a08b58b698f0cf37da373070)
Signed-off-by: Pindar Yang <pindaryang@google.com>
Change-Id: I9bf6f540b4eb23ea5641fb3efe6f3e621d7b6151
-rw-r--r-- | net/sched/cls_fw.c | 10 |
1 files changed, 5 insertions, 5 deletions
diff --git a/net/sched/cls_fw.c b/net/sched/cls_fw.c index cb2c62605fc7..5284a473c697 100644 --- a/net/sched/cls_fw.c +++ b/net/sched/cls_fw.c @@ -221,11 +221,6 @@ static int fw_set_parms(struct net *net, struct tcf_proto *tp, if (err < 0) return err; - if (tb[TCA_FW_CLASSID]) { - f->res.classid = nla_get_u32(tb[TCA_FW_CLASSID]); - tcf_bind_filter(tp, &f->res, base); - } - #ifdef CONFIG_NET_CLS_IND if (tb[TCA_FW_INDEV]) { int ret; @@ -244,6 +239,11 @@ static int fw_set_parms(struct net *net, struct tcf_proto *tp, } else if (head->mask != 0xFFFFFFFF) return err; + if (tb[TCA_FW_CLASSID]) { + f->res.classid = nla_get_u32(tb[TCA_FW_CLASSID]); + tcf_bind_filter(tp, &f->res, base); + } + return 0; } |