UPSTREAM: staging: most: net: fix buffer overflow
If the length of the socket buffer is 0xFFFFFFFF (max size for an
unsigned int), then payload_len becomes 0xFFFFFFF1 after subtracting 14
(ETH_HLEN). Then, mdp_len is set to payload_len + 16 (MDP_HDR_LEN)
which overflows and results in a value of 2. These values for
payload_len and mdp_len will pass current buffer size checks.
This patch checks if derived from skb->len sum may overflow.
The check is based on the following idea:
For any `unsigned V1, V2` and derived `unsigned SUM = V1 + V2`,
`V1 + V2` overflows iif `SUM < V1`.
Reported-by: Greg Kroah-Hartman <email@example.com>
Signed-off-by: Andrey Shvetsov <firstname.lastname@example.org>
Cc: stable <email@example.com>
Signed-off-by: Greg Kroah-Hartman <firstname.lastname@example.org>
(cherry picked from commit 4d1356ac12f4d5180d0df345d85ff0ee42b89c72)
Signed-off-by: Greg Kroah-Hartman <email@example.com>
1 file changed