You need to sign in or sign up before continuing.
netfilter: nfnetlink_cttimeout: pass default timeout policy to obj_to_nlattr
mainline inclusion from mainline-4.20 commit 8866df9264a34e675b4ee8a151db819b87cce2d3 category: bugfix bugzilla: 6008 CVE: NA ------------------------------------------------- Otherwise, we hit a NULL pointer deference since handlers always assume default timeout policy is passed. netlink: 24 bytes leftover after parsing attributes in process `syz-executor2'. kasan: CONFIG_KASAN_INLINE enabled kasan: GPF could be caused by NULL-ptr deref or user memory access general protection fault: 0000 [#1] PREEMPT SMP KASAN CPU: 0 PID: 9575 Comm: syz-executor1 Not tainted 4.19.0+ #312 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011 RIP: 0010:icmp_timeout_obj_to_nlattr+0x77/0x170 net/netfilter/nf_conntrack_proto_icmp.c:297 Fixes: c779e849 ("netfilter: conntrack: remove get_timeout() indirection") Reported-by: NEric Dumazet <eric.dumazet@gmail.com> Signed-off-by: NPablo Neira Ayuso <pablo@netfilter.org> Signed-off-by: NYueHaibing <yuehaibing@huawei.com> Conflicts: net/netfilter/nfnetlink_cttimeout.c Reviewed-by: NMao Wenan <maowenan@huawei.com> Signed-off-by: NYang Yingliang <yangyingliang@huawei.com>
Showing
想要评论请 注册 或 登录