forked from Minki/linux
netrom: avoid overflows in nr_setsockopt()
Check setsockopt arguments to avoid overflows and return -EINVAL for too large arguments. Signed-off-by: Xi Wang <xi.wang@gmail.com> Signed-off-by: David S. Miller <davem@davemloft.net>
This commit is contained in:
parent
ba1cffe025
commit
32288eb4d9
@ -306,26 +306,26 @@ static int nr_setsockopt(struct socket *sock, int level, int optname,
|
||||
{
|
||||
struct sock *sk = sock->sk;
|
||||
struct nr_sock *nr = nr_sk(sk);
|
||||
int opt;
|
||||
unsigned long opt;
|
||||
|
||||
if (level != SOL_NETROM)
|
||||
return -ENOPROTOOPT;
|
||||
|
||||
if (optlen < sizeof(int))
|
||||
if (optlen < sizeof(unsigned int))
|
||||
return -EINVAL;
|
||||
|
||||
if (get_user(opt, (int __user *)optval))
|
||||
if (get_user(opt, (unsigned int __user *)optval))
|
||||
return -EFAULT;
|
||||
|
||||
switch (optname) {
|
||||
case NETROM_T1:
|
||||
if (opt < 1)
|
||||
if (opt < 1 || opt > ULONG_MAX / HZ)
|
||||
return -EINVAL;
|
||||
nr->t1 = opt * HZ;
|
||||
return 0;
|
||||
|
||||
case NETROM_T2:
|
||||
if (opt < 1)
|
||||
if (opt < 1 || opt > ULONG_MAX / HZ)
|
||||
return -EINVAL;
|
||||
nr->t2 = opt * HZ;
|
||||
return 0;
|
||||
@ -337,13 +337,13 @@ static int nr_setsockopt(struct socket *sock, int level, int optname,
|
||||
return 0;
|
||||
|
||||
case NETROM_T4:
|
||||
if (opt < 1)
|
||||
if (opt < 1 || opt > ULONG_MAX / HZ)
|
||||
return -EINVAL;
|
||||
nr->t4 = opt * HZ;
|
||||
return 0;
|
||||
|
||||
case NETROM_IDLE:
|
||||
if (opt < 0)
|
||||
if (opt > ULONG_MAX / (60 * HZ))
|
||||
return -EINVAL;
|
||||
nr->idle = opt * 60 * HZ;
|
||||
return 0;
|
||||
|
Loading…
Reference in New Issue
Block a user