svn commit: r365255 - releng/11.3/sys/netinet6
Gordon Tetlow
gordon at FreeBSD.org
Wed Sep 2 16:23:16 UTC 2020
Author: gordon
Date: Wed Sep 2 16:23:15 2020
New Revision: 365255
URL: https://svnweb.freebsd.org/changeset/base/365255
Log:
Fix IPv6 Hop-by-Hop options use-after-free.
Approved by: so
Security: FreeBSD-SA-20:24.ipv6
Security: CVE-2020-7462
Modified:
releng/11.3/sys/netinet6/ip6_input.c
Modified: releng/11.3/sys/netinet6/ip6_input.c
==============================================================================
--- releng/11.3/sys/netinet6/ip6_input.c Wed Sep 2 16:22:14 2020 (r365254)
+++ releng/11.3/sys/netinet6/ip6_input.c Wed Sep 2 16:23:15 2020 (r365255)
@@ -402,20 +402,22 @@ VNET_SYSUNINIT(inet6, SI_SUB_PROTO_DOMAIN, SI_ORDER_TH
#endif
static int
-ip6_input_hbh(struct mbuf *m, uint32_t *plen, uint32_t *rtalert, int *off,
+ip6_input_hbh(struct mbuf **mp, uint32_t *plen, uint32_t *rtalert, int *off,
int *nxt, int *ours)
{
+ struct mbuf *m;
struct ip6_hdr *ip6;
struct ip6_hbh *hbh;
- if (ip6_hopopts_input(plen, rtalert, &m, off)) {
+ if (ip6_hopopts_input(plen, rtalert, mp, off)) {
#if 0 /*touches NULL pointer*/
- in6_ifstat_inc(m->m_pkthdr.rcvif, ifs6_in_discard);
+ in6_ifstat_inc((*mp)->m_pkthdr.rcvif, ifs6_in_discard);
#endif
goto out; /* m have already been freed */
}
/* adjust pointer */
+ m = *mp;
ip6 = mtod(m, struct ip6_hdr *);
/*
@@ -855,7 +857,7 @@ passin:
*/
plen = (u_int32_t)ntohs(ip6->ip6_plen);
if (ip6->ip6_nxt == IPPROTO_HOPOPTS) {
- if (ip6_input_hbh(m, &plen, &rtalert, &off, &nxt, &ours) != 0)
+ if (ip6_input_hbh(&m, &plen, &rtalert, &off, &nxt, &ours) != 0)
return;
} else
nxt = ip6->ip6_nxt;
More information about the svn-src-releng
mailing list