svn commit: r360343 - stable/11/sys/netpfil/pf
Kristof Provost
kp at FreeBSD.org
Sun Apr 26 16:13:52 UTC 2020
Author: kp
Date: Sun Apr 26 16:13:51 2020
New Revision: 360343
URL: https://svnweb.freebsd.org/changeset/base/360343
Log:
MFC r360098:
pf: Improve ioctl() input validation
Both DIOCCHANGEADDR and DIOCADDADDR take a struct pf_pooladdr from
userspace. They failed to validate the dyn pointer contained in its
struct pf_addr_wrap member structure.
This triggered assertion failures under fuzz testing in
pfi_dynaddr_setup(). Happily the dyn variable was overruled there, but
we should verify that it's set to NULL anyway.
Reported-by: syzbot+93e93150bc29f9b4b85f at syzkaller.appspotmail.com
Modified:
stable/11/sys/netpfil/pf/pf_ioctl.c
Directory Properties:
stable/11/ (props changed)
Modified: stable/11/sys/netpfil/pf/pf_ioctl.c
==============================================================================
--- stable/11/sys/netpfil/pf/pf_ioctl.c Sun Apr 26 16:13:50 2020 (r360342)
+++ stable/11/sys/netpfil/pf/pf_ioctl.c Sun Apr 26 16:13:51 2020 (r360343)
@@ -2229,6 +2229,10 @@ DIOCGETSTATES_full:
error = EINVAL;
break;
}
+ if (pp->addr.addr.p.dyn != NULL) {
+ error = EINVAL;
+ break;
+ }
pa = malloc(sizeof(*pa), M_PFRULE, M_WAITOK);
bcopy(&pp->addr, pa, sizeof(struct pf_pooladdr));
if (pa->ifname[0])
@@ -2325,6 +2329,10 @@ DIOCGETSTATES_full:
if (pca->addr.addr.type != PF_ADDR_ADDRMASK &&
pca->addr.addr.type != PF_ADDR_DYNIFTL &&
pca->addr.addr.type != PF_ADDR_TABLE) {
+ error = EINVAL;
+ break;
+ }
+ if (pca->addr.addr.p.dyn != NULL) {
error = EINVAL;
break;
}
More information about the svn-src-stable
mailing list