提交 b5f15ac4 编写于 作者: V Vasiliy Kulikov 提交者: Patrick McHardy

ipv4: netfilter: ip_tables: fix information leak to userland

Structure ipt_getinfo is copied to userland with the field "name"
that has the last elements unitialized.  It leads to leaking of
contents of kernel stack memory.
Signed-off-by: NVasiliy Kulikov <segooon@gmail.com>
Signed-off-by: NPatrick McHardy <kaber@trash.net>
上级 1a8b7a67
...@@ -1124,6 +1124,7 @@ static int get_info(struct net *net, void __user *user, ...@@ -1124,6 +1124,7 @@ static int get_info(struct net *net, void __user *user,
private = &tmp; private = &tmp;
} }
#endif #endif
memset(&info, 0, sizeof(info));
info.valid_hooks = t->valid_hooks; info.valid_hooks = t->valid_hooks;
memcpy(info.hook_entry, private->hook_entry, memcpy(info.hook_entry, private->hook_entry,
sizeof(info.hook_entry)); sizeof(info.hook_entry));
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册