Skip to content

Commit 86587f3

Browse files
PhilPottergregkh
authored andcommitted
net: hsr: check skb can contain struct hsr_ethhdr in fill_frame_info
[ Upstream commit 2e9f609 ] Check at start of fill_frame_info that the MAC header in the supplied skb is large enough to fit a struct hsr_ethhdr, as otherwise this is not a valid HSR frame. If it is too small, return an error which will then cause the callers to clean up the skb. Fixes a KMSAN-found uninit-value bug reported by syzbot at: https://syzkaller.appspot.com/bug?id=f7e9b601f1414f814f7602a82b6619a8d80bce3f Reported-by: syzbot+e267bed19bfc5478fb33@syzkaller.appspotmail.com Signed-off-by: Phillip Potter <phil@philpotter.co.uk> Signed-off-by: David S. Miller <davem@davemloft.net> Signed-off-by: Sasha Levin <sashal@kernel.org>
1 parent 82646b1 commit 86587f3

1 file changed

Lines changed: 4 additions & 0 deletions

File tree

net/hsr/hsr_forward.c

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -493,6 +493,10 @@ static int fill_frame_info(struct hsr_frame_info *frame,
493493
struct ethhdr *ethhdr;
494494
__be16 proto;
495495

496+
/* Check if skb contains hsr_ethhdr */
497+
if (skb->mac_len < sizeof(struct hsr_ethhdr))
498+
return -EINVAL;
499+
496500
memset(frame, 0, sizeof(*frame));
497501
frame->is_supervision = is_supervision_frame(port->hsr, skb);
498502
frame->node_src = hsr_get_node(port, &hsr->node_db, skb,

0 commit comments

Comments
 (0)