diff options
author | Sabrina Dubroca <sd@queasysnail.net> | 2015-10-15 14:25:03 +0200 |
---|---|---|
committer | Jiri Slaby <jslaby@suse.cz> | 2015-10-26 13:36:01 +0100 |
commit | 3e1ac3aafbd0cf1f7c81cb7099a8a1d0407e021d (patch) | |
tree | d09c6fb8d433861dcc0d874fea2a72aa17e7af4d /net/core | |
parent | 0072abfc723f192261b5817f1f058bfc46796d19 (diff) | |
download | lwn-3e1ac3aafbd0cf1f7c81cb7099a8a1d0407e021d.tar.gz lwn-3e1ac3aafbd0cf1f7c81cb7099a8a1d0407e021d.zip |
net: add length argument to skb_copy_and_csum_datagram_iovec
Without this length argument, we can read past the end of the iovec in
memcpy_toiovec because we have no way of knowing the total length of the
iovec's buffers.
This is needed for stable kernels where 89c22d8c3b27 ("net: Fix skb
csum races when peeking") has been backported but that don't have the
ioviter conversion, which is almost all the stable trees <= 3.18.
This also fixes a kernel crash for NFS servers when the client uses
-onfsvers=3,proto=udp to mount the export.
Signed-off-by: Sabrina Dubroca <sd@queasysnail.net>
Reviewed-by: Hannes Frederic Sowa <hannes@stressinduktion.org>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
Diffstat (limited to 'net/core')
-rw-r--r-- | net/core/datagram.c | 6 |
1 files changed, 5 insertions, 1 deletions
diff --git a/net/core/datagram.c b/net/core/datagram.c index 98e3d61e7476..f22f120771ef 100644 --- a/net/core/datagram.c +++ b/net/core/datagram.c @@ -796,6 +796,7 @@ EXPORT_SYMBOL(__skb_checksum_complete); * @skb: skbuff * @hlen: hardware length * @iov: io vector + * @len: amount of data to copy from skb to iov * * Caller _must_ check that skb will fit to this iovec. * @@ -805,11 +806,14 @@ EXPORT_SYMBOL(__skb_checksum_complete); * can be modified! */ int skb_copy_and_csum_datagram_iovec(struct sk_buff *skb, - int hlen, struct iovec *iov) + int hlen, struct iovec *iov, int len) { __wsum csum; int chunk = skb->len - hlen; + if (chunk > len) + chunk = len; + if (!chunk) return 0; |