From patchwork Wed Mar 28 17:23:04 2018 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Roland Dreier X-Patchwork-Id: 10313689 Return-Path: Received: from mail.wl.linuxfoundation.org (pdx-wl-mail.web.codeaurora.org [172.30.200.125]) by pdx-korg-patchwork.web.codeaurora.org (Postfix) with ESMTP id DD32A600F6 for ; Wed, 28 Mar 2018 17:23:34 +0000 (UTC) Received: from mail.wl.linuxfoundation.org (localhost [127.0.0.1]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id CC55B28C3A for ; Wed, 28 Mar 2018 17:23:34 +0000 (UTC) Received: by mail.wl.linuxfoundation.org (Postfix, from userid 486) id CA99F29FBE; Wed, 28 Mar 2018 17:23:34 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on pdx-wl-mail.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-6.8 required=2.0 tests=BAYES_00,DKIM_SIGNED, RCVD_IN_DNSWL_HI,T_DKIM_INVALID autolearn=ham version=3.3.1 Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 13F1D29FFF for ; Wed, 28 Mar 2018 17:23:12 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1752161AbeC1RXL (ORCPT ); Wed, 28 Mar 2018 13:23:11 -0400 Received: from mail-pg0-f68.google.com ([74.125.83.68]:45659 "EHLO mail-pg0-f68.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751976AbeC1RXK (ORCPT ); Wed, 28 Mar 2018 13:23:10 -0400 Received: by mail-pg0-f68.google.com with SMTP id y63so1181602pgy.12 for ; Wed, 28 Mar 2018 10:23:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=purestorage.com; s=google; h=sender:from:to:cc:subject:date:message-id; bh=0N3mwXKpSz1FgrcA7iv0SiGFao5UifdOY01jwJA3NrU=; b=TiaR1z+MyMUJiSaG4NT/IgKbnZQZbIvGE4sv6O+GsAFi6BiPo7UeWeKI4RqnuWwGlv P3HMfD3/yXwZUhSCS7eqgWnTPaA31u5L5VL1aIjl86WECnO4q40AeU8G8+6w6tIOPykm AALhvTIckRHgIShgVzeoQ+M95ZC4j2tNhKNHE= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:sender:from:to:cc:subject:date:message-id; bh=0N3mwXKpSz1FgrcA7iv0SiGFao5UifdOY01jwJA3NrU=; b=tgPTS5SJ4eWGSdCnxC/iZtC6vqFLGOpoqAAgN6HIylOMtf9+suAAl8AiimtzwRIpkf 5QCp6HgNT+04Nf2unxODtqjaIgdOTYgMnxL5+umxnjSwY1nKciIO9tT8Cv7GzkWtetdM 4hVkkWdBLdscTnQ0EmElx374AbXD598kkpE5qg6GlA2asgJ6VvXY+IgoW3aFlLmXmmOp GyyUR6BK0jCPBYwwVdHXxTqxT7J/zwcX1lWlEeQGR+rDgfkAMOmBU0MXc8apuELtJinT KGCQx0l0RqfugMrCAC/ZEmIWyZLefwaAwlDdu0yjl+n5Xoh1ZxM2Dnu1svxvfRNd/bN4 xEcA== X-Gm-Message-State: AElRT7ExK40s0YC9v7tMvPAOjxdTJxujiBIf1A66HIzvJ7RV0dyxshjT jmA3XczEql36LWL33B18z83gtA== X-Google-Smtp-Source: AIpwx49DVDR2bUxyK+aUakC4I4GqXHrT3mD10E6aL8ughlPr7A+4IaBJvHekCYdaqisGHipTIf+i1A== X-Received: by 2002:a17:902:24c:: with SMTP id 70-v6mr4665333plc.384.1522257789958; Wed, 28 Mar 2018 10:23:09 -0700 (PDT) Received: from roland-x1-yoga.purestorage.com ([64.84.68.252]) by smtp.gmail.com with ESMTPSA id q75sm9303202pfj.99.2018.03.28.10.23.07 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Wed, 28 Mar 2018 10:23:07 -0700 (PDT) From: Roland Dreier To: Doug Ledford , Jason Gunthorpe , Leon Romanovsky , Sean Hefty , syzbot Cc: linux-rdma@vger.kernel.org Subject: [PATCH v2] RDMA/ucma: Don't allow AF_IB in ucma_join_ip_multicast() Date: Wed, 28 Mar 2018 10:23:04 -0700 Message-Id: <20180328172304.7123-1-roland@kernel.org> X-Mailer: git-send-email 2.15.1 Sender: linux-rdma-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-rdma@vger.kernel.org X-Virus-Scanned: ClamAV using ClamSMTP From: Roland Dreier If userspace passes a sockaddr with sa_family == AF_IB to the ucma join IP multicast command, the kernel will memcpy() past the end of the cmd.addr buffer, because sockaddr_ib is bigger than sockaddr_in6. Fix this by returning EINVAL if the addr_size we get back is bigger than the address buffers we're copying between. Reported-and-tested-by: syzbot+6800425d54ed3ed8135d@syzkaller.appspotmail.com Signed-off-by: Roland Dreier --- #syz test: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux-2.6.git master drivers/infiniband/core/ucma.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/drivers/infiniband/core/ucma.c b/drivers/infiniband/core/ucma.c index e5a1e7d81326..7684fd54318a 100644 --- a/drivers/infiniband/core/ucma.c +++ b/drivers/infiniband/core/ucma.c @@ -1427,7 +1427,8 @@ static ssize_t ucma_join_ip_multicast(struct ucma_file *file, join_cmd.uid = cmd.uid; join_cmd.id = cmd.id; join_cmd.addr_size = rdma_addr_size((struct sockaddr *) &cmd.addr); - if (!join_cmd.addr_size) + if (!join_cmd.addr_size || + join_cmd.addr_size > min(sizeof(cmd.addr), sizeof(join_cmd.addr))) return -EINVAL; join_cmd.join_flags = RDMA_MC_JOIN_FLAG_FULLMEMBER;