diff options
author | Christoph Hellwig <hch@lst.de> | 2020-07-23 08:08:45 +0200 |
---|---|---|
committer | David S. Miller <davem@davemloft.net> | 2020-07-24 15:41:53 -0700 |
commit | d200cf624c9247ab52b67d34d9e198262a23df31 (patch) | |
tree | 7eb16c965917dd917b545cccfc5a4d1fff1854d6 /net | |
parent | c9ffebdde8deccf9ea3a7a97bcd84de0a35ddad7 (diff) | |
download | linux-d200cf624c9247ab52b67d34d9e198262a23df31.tar.bz2 |
bpfilter: reject kernel addresses
The bpfilter user mode helper processes the optval address using
process_vm_readv. Don't send it kernel addresses fed under
set_fs(KERNEL_DS) as that won't work.
Signed-off-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: David S. Miller <davem@davemloft.net>
Diffstat (limited to 'net')
-rw-r--r-- | net/bpfilter/bpfilter_kern.c | 4 |
1 files changed, 4 insertions, 0 deletions
diff --git a/net/bpfilter/bpfilter_kern.c b/net/bpfilter/bpfilter_kern.c index 78d561f2c54d..00540457e5f4 100644 --- a/net/bpfilter/bpfilter_kern.c +++ b/net/bpfilter/bpfilter_kern.c @@ -70,6 +70,10 @@ static int bpfilter_process_sockopt(struct sock *sk, int optname, .addr = (uintptr_t)optval, .len = optlen, }; + if (uaccess_kernel()) { + pr_err("kernel access not supported\n"); + return -EFAULT; + } return bpfilter_send_req(&req); } |