summaryrefslogtreecommitdiffstats
path: root/net
diff options
context:
space:
mode:
authorEric Dumazet <edumazet@google.com>2023-01-20 13:31:40 +0000
committerJakub Kicinski <kuba@kernel.org>2023-01-23 21:37:39 -0800
commit5e9398a26a92fc402d82ce1f97cc67d832527da0 (patch)
tree306205c5751a295601e5889e5ae3fb9d0bb385eb /net
parent1d1d63b612801b3f0a39b7d4467cad0abd60e5c8 (diff)
downloadlinux-stable-5e9398a26a92fc402d82ce1f97cc67d832527da0.tar.gz
linux-stable-5e9398a26a92fc402d82ce1f97cc67d832527da0.tar.bz2
linux-stable-5e9398a26a92fc402d82ce1f97cc67d832527da0.zip
ipv4: prevent potential spectre v1 gadget in fib_metrics_match()
if (!type) continue; if (type > RTAX_MAX) return false; ... fi_val = fi->fib_metrics->metrics[type - 1]; @type being used as an array index, we need to prevent cpu speculation or risk leaking kernel memory content. Fixes: 5f9ae3d9e7e4 ("ipv4: do metrics match when looking up and deleting a route") Signed-off-by: Eric Dumazet <edumazet@google.com> Link: https://lore.kernel.org/r/20230120133140.3624204-1-edumazet@google.com Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Diffstat (limited to 'net')
-rw-r--r--net/ipv4/fib_semantics.c2
1 files changed, 2 insertions, 0 deletions
diff --git a/net/ipv4/fib_semantics.c b/net/ipv4/fib_semantics.c
index ce9ff3c62e84..3bb890a40ed7 100644
--- a/net/ipv4/fib_semantics.c
+++ b/net/ipv4/fib_semantics.c
@@ -30,6 +30,7 @@
#include <linux/slab.h>
#include <linux/netlink.h>
#include <linux/hash.h>
+#include <linux/nospec.h>
#include <net/arp.h>
#include <net/inet_dscp.h>
@@ -1022,6 +1023,7 @@ bool fib_metrics_match(struct fib_config *cfg, struct fib_info *fi)
if (type > RTAX_MAX)
return false;
+ type = array_index_nospec(type, RTAX_MAX + 1);
if (type == RTAX_CC_ALGO) {
char tmp[TCP_CA_NAME_MAX];
bool ecn_ca = false;