summaryrefslogtreecommitdiff
path: root/net
diff options
context:
space:
mode:
authorDouya Le <ldy3087146292@gmail.com>2026-06-07 17:35:49 +0800
committerIlya Dryomov <idryomov@gmail.com>2026-07-23 20:29:41 +0200
commitd3c32939fa0e3ee9b883b9a0fd1972c5c444e3d0 (patch)
tree037172b66463501c1465e584ac81bf1371abd83f /net
parentcbf59617cd715219e84c50d106a3d0e1e8ba054e (diff)
downloadlinux-next-d3c32939fa0e3ee9b883b9a0fd1972c5c444e3d0.tar.gz
linux-next-d3c32939fa0e3ee9b883b9a0fd1972c5c444e3d0.zip
libceph: bound get_version reply decode to front len
handle_get_version_reply() uses msg->front_alloc_len as the decode boundary for MON_GET_VERSION_REPLY. That is the size of the reused reply buffer, not the number of bytes actually received. A truncated reply can therefore pass ceph_decode_need() and decode the second u64 from stale tail bytes left in the buffer by an earlier message, causing an uninitialized memory read. Use msg->front.iov_len as the receive-side decode boundary, matching other libceph reply handlers and limiting decoding to the bytes that were actually read from the wire. Cc: stable@vger.kernel.org Fixes: 513a8243d67f ("libceph: mon_get_version request infrastructure") Reported-by: Yuan Tan <yuantan098@gmail.com> Reported-by: Zhengchuan Liang <zcliangcn@gmail.com> Reported-by: Xin Liu <bird@lzu.edu.cn> Assisted-by: Codex:GPT-5.4 Signed-off-by: Douya Le <ldy3087146292@gmail.com> Signed-off-by: Ren Wei <n05ec@lzu.edu.cn> Reviewed-by: Viacheslav Dubeyko <slava@dubeyko.com> Signed-off-by: Ilya Dryomov <idryomov@gmail.com>
Diffstat (limited to 'net')
-rw-r--r--net/ceph/mon_client.c2
1 files changed, 1 insertions, 1 deletions
diff --git a/net/ceph/mon_client.c b/net/ceph/mon_client.c
index 24acdd580e79..c56457378d00 100644
--- a/net/ceph/mon_client.c
+++ b/net/ceph/mon_client.c
@@ -821,7 +821,7 @@ static void handle_get_version_reply(struct ceph_mon_client *monc,
struct ceph_mon_generic_request *req;
u64 tid = le64_to_cpu(msg->hdr.tid);
void *p = msg->front.iov_base;
- void *end = p + msg->front_alloc_len;
+ void *const end = p + msg->front.iov_len;
u64 handle;
dout("%s msg %p tid %llu\n", __func__, msg, tid);