summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorKangjie Lu <kangjielu@gmail.com>2016-05-03 16:35:05 -0400
committerBen Hutchings <ben@decadent.org.uk>2016-06-15 21:28:15 +0100
commit3ec6a22dc6ded2c350e1d47513d316c55e9330c1 (patch)
treef79b2b71c60bfff42d9cf7bace9a3ec6836efb8e
parent9f9aa476de1b6bd8fe179dfd9b204972c8c98791 (diff)
downloadlinux-stable-3ec6a22dc6ded2c350e1d47513d316c55e9330c1.tar.gz
linux-stable-3ec6a22dc6ded2c350e1d47513d316c55e9330c1.tar.bz2
linux-stable-3ec6a22dc6ded2c350e1d47513d316c55e9330c1.zip
net: fix infoleak in llc
commit b8670c09f37bdf2847cc44f36511a53afc6161fd upstream. The stack object “info” has a total size of 12 bytes. Its last byte is padding which is not initialized and leaked via “put_cmsg”. Signed-off-by: Kangjie Lu <kjlu@gatech.edu> Signed-off-by: David S. Miller <davem@davemloft.net> Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
-rw-r--r--net/llc/af_llc.c1
1 files changed, 1 insertions, 0 deletions
diff --git a/net/llc/af_llc.c b/net/llc/af_llc.c
index f432d7b6d93a..7752b2ffbc43 100644
--- a/net/llc/af_llc.c
+++ b/net/llc/af_llc.c
@@ -627,6 +627,7 @@ static void llc_cmsg_rcv(struct msghdr *msg, struct sk_buff *skb)
if (llc->cmsg_flags & LLC_CMSG_PKTINFO) {
struct llc_pktinfo info;
+ memset(&info, 0, sizeof(info));
info.lpi_ifindex = llc_sk(skb->sk)->dev->ifindex;
llc_pdu_decode_dsap(skb, &info.lpi_sap);
llc_pdu_decode_da(skb, info.lpi_mac);