提交 0f04cfd0 编写于 作者: J Jeff Mahoney 提交者: David S. Miller

net sched: fix kernel leak in act_police

While reviewing commit 1c40be12, I
 audited other users of tc_action_ops->dump for information leaks.

 That commit covered almost all of them but act_police still had a leak.

 opt.limit and opt.capab aren't zeroed out before the structure is
 passed out.

 This patch uses the C99 initializers to zero everything unused out.
Signed-off-by: NJeff Mahoney <jeffm@suse.com>
Acked-by: NJeff Mahoney <jeffm@suse.com>
Signed-off-by: NDavid S. Miller <davem@davemloft.net>
上级 78b620ce
...@@ -350,22 +350,19 @@ tcf_act_police_dump(struct sk_buff *skb, struct tc_action *a, int bind, int ref) ...@@ -350,22 +350,19 @@ tcf_act_police_dump(struct sk_buff *skb, struct tc_action *a, int bind, int ref)
{ {
unsigned char *b = skb_tail_pointer(skb); unsigned char *b = skb_tail_pointer(skb);
struct tcf_police *police = a->priv; struct tcf_police *police = a->priv;
struct tc_police opt; struct tc_police opt = {
.index = police->tcf_index,
opt.index = police->tcf_index; .action = police->tcf_action,
opt.action = police->tcf_action; .mtu = police->tcfp_mtu,
opt.mtu = police->tcfp_mtu; .burst = police->tcfp_burst,
opt.burst = police->tcfp_burst; .refcnt = police->tcf_refcnt - ref,
opt.refcnt = police->tcf_refcnt - ref; .bindcnt = police->tcf_bindcnt - bind,
opt.bindcnt = police->tcf_bindcnt - bind; };
if (police->tcfp_R_tab) if (police->tcfp_R_tab)
opt.rate = police->tcfp_R_tab->rate; opt.rate = police->tcfp_R_tab->rate;
else
memset(&opt.rate, 0, sizeof(opt.rate));
if (police->tcfp_P_tab) if (police->tcfp_P_tab)
opt.peakrate = police->tcfp_P_tab->rate; opt.peakrate = police->tcfp_P_tab->rate;
else
memset(&opt.peakrate, 0, sizeof(opt.peakrate));
NLA_PUT(skb, TCA_POLICE_TBF, sizeof(opt), &opt); NLA_PUT(skb, TCA_POLICE_TBF, sizeof(opt), &opt);
if (police->tcfp_result) if (police->tcfp_result)
NLA_PUT_U32(skb, TCA_POLICE_RESULT, police->tcfp_result); NLA_PUT_U32(skb, TCA_POLICE_RESULT, police->tcfp_result);
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册