rpms/kernel/F-13 ethtool-fix-buffer-overflow.patch, NONE, 1.1 kernel.spec, 1.2081, 1.2082

Chuck Ebbert cebbert at fedoraproject.org
Tue Jul 6 14:02:16 UTC 2010


Author: cebbert

Update of /cvs/pkgs/rpms/kernel/F-13
In directory cvs01.phx2.fedoraproject.org:/tmp/cvs-serv30158

Modified Files:
	kernel.spec 
Added Files:
	ethtool-fix-buffer-overflow.patch 
Log Message:
ethtool-fix-buffer-overflow.patch: ethtool buffer overflow (CVE-2010-2478)

ethtool-fix-buffer-overflow.patch:
 ethtool.c |    5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

--- NEW FILE ethtool-fix-buffer-overflow.patch ---
From: Ben Hutchings <bhutchings at solarflare.com>
Date: Mon, 28 Jun 2010 08:44:07 +0000 (+0000)
Subject: ethtool: Fix potential kernel buffer overflow in ETHTOOL_GRXCLSRLALL
X-Git-Url: http://git.kernel.org/?p=linux%2Fkernel%2Fgit%2Fdavem%2Fnet-2.6.git;a=commitdiff_plain;h=db048b69037e7fa6a7d9e95a1271a50dc08ae233

ethtool: Fix potential kernel buffer overflow in ETHTOOL_GRXCLSRLALL

On a 32-bit machine, info.rule_cnt >= 0x40000000 leads to integer
overflow and the buffer may be smaller than needed.  Since
ETHTOOL_GRXCLSRLALL is unprivileged, this can presumably be used for at
least denial of service.

Signed-off-by: Ben Hutchings <bhutchings at solarflare.com>
Cc: stable at kernel.org
Signed-off-by: David S. Miller <davem at davemloft.net>
---

diff --git a/net/core/ethtool.c b/net/core/ethtool.c
index a0f4964..a3a7e9a 100644
--- a/net/core/ethtool.c
+++ b/net/core/ethtool.c
@@ -347,8 +347,9 @@ static noinline_for_stack int ethtool_get_rxnfc(struct net_device *dev,
 
 	if (info.cmd == ETHTOOL_GRXCLSRLALL) {
 		if (info.rule_cnt > 0) {
-			rule_buf = kmalloc(info.rule_cnt * sizeof(u32),
-					   GFP_USER);
+			if (info.rule_cnt <= KMALLOC_MAX_SIZE / sizeof(u32))
+				rule_buf = kmalloc(info.rule_cnt * sizeof(u32),
+						   GFP_USER);
 			if (!rule_buf)
 				return -ENOMEM;
 		}


Index: kernel.spec
===================================================================
RCS file: /cvs/pkgs/rpms/kernel/F-13/kernel.spec,v
retrieving revision 1.2081
retrieving revision 1.2082
diff -u -p -r1.2081 -r1.2082
--- kernel.spec	6 Jul 2010 13:47:17 -0000	1.2081
+++ kernel.spec	6 Jul 2010 14:02:15 -0000	1.2082
@@ -860,6 +860,7 @@ Patch13010: rt2x00-rt2800-Make-rt30xx-an
 Patch13020: iwlwifi-cancel-scan-watchdog-in-iwl_bg_abort_scan.patch
 
 Patch13030: sched-fix-over-scheduling-bug.patch
+Patch13040: ethtool-fix-buffer-overflow.patch
 
 %endif
 
@@ -1569,6 +1570,9 @@ ApplyPatch iwlwifi-cancel-scan-watchdog-
 # fix performance problem with CGROUPS
 ApplyPatch sched-fix-over-scheduling-bug.patch
 
+# CVE-2010-2478
+ApplyPatch ethtool-fix-buffer-overflow.patch
+
 # END OF PATCH APPLICATIONS
 
 %endif
@@ -2219,6 +2223,9 @@ fi
 # and build.
 
 %changelog
+* Tue Jul 06 2010 Chuck Ebbert <cebbert at redhat.com> 2.6.33.6-145
+- ethtool-fix-buffer-overflow.patch: ethtool buffer overflow (CVE-2010-2478)
+
 * Tue Jul 06 2010 Chuck Ebbert <cebbert at redhat.com> 2.6.33.6-144
 - sched-fix-over-scheduling-bug.patch: fix scheduler bug with CGROUPS
 



More information about the scm-commits mailing list