Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 26 Apr 2020 16:13:52 +0000 (UTC)
From:      Kristof Provost <kp@FreeBSD.org>
To:        src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-stable@freebsd.org, svn-src-stable-11@freebsd.org
Subject:   svn commit: r360343 - stable/11/sys/netpfil/pf
Message-ID:  <202004261613.03QGDq24095297@repo.freebsd.org>

next in thread | raw e-mail | index | archive | help
Author: kp
Date: Sun Apr 26 16:13:51 2020
New Revision: 360343
URL: https://svnweb.freebsd.org/changeset/base/360343

Log:
  MFC r360098:
  
  pf: Improve ioctl() input validation
  
  Both DIOCCHANGEADDR and DIOCADDADDR take a struct pf_pooladdr from
  userspace. They failed to validate the dyn pointer contained in its
  struct pf_addr_wrap member structure.
  
  This triggered assertion failures under fuzz testing in
  pfi_dynaddr_setup(). Happily the dyn variable was overruled there, but
  we should verify that it's set to NULL anyway.
  
  Reported-by:	syzbot+93e93150bc29f9b4b85f@syzkaller.appspotmail.com

Modified:
  stable/11/sys/netpfil/pf/pf_ioctl.c
Directory Properties:
  stable/11/   (props changed)

Modified: stable/11/sys/netpfil/pf/pf_ioctl.c
==============================================================================
--- stable/11/sys/netpfil/pf/pf_ioctl.c	Sun Apr 26 16:13:50 2020	(r360342)
+++ stable/11/sys/netpfil/pf/pf_ioctl.c	Sun Apr 26 16:13:51 2020	(r360343)
@@ -2229,6 +2229,10 @@ DIOCGETSTATES_full:
 			error = EINVAL;
 			break;
 		}
+		if (pp->addr.addr.p.dyn != NULL) {
+			error = EINVAL;
+			break;
+		}
 		pa = malloc(sizeof(*pa), M_PFRULE, M_WAITOK);
 		bcopy(&pp->addr, pa, sizeof(struct pf_pooladdr));
 		if (pa->ifname[0])
@@ -2325,6 +2329,10 @@ DIOCGETSTATES_full:
 		if (pca->addr.addr.type != PF_ADDR_ADDRMASK &&
 		    pca->addr.addr.type != PF_ADDR_DYNIFTL &&
 		    pca->addr.addr.type != PF_ADDR_TABLE) {
+			error = EINVAL;
+			break;
+		}
+		if (pca->addr.addr.p.dyn != NULL) {
 			error = EINVAL;
 			break;
 		}



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?202004261613.03QGDq24095297>