af_key: Fix send_acquire race with pfkey_register
authorHerbert Xu <herbert@gondor.apana.org.au>
Tue, 25 Oct 2022 06:06:48 +0000 (14:06 +0800)
committerSteffen Klassert <steffen.klassert@secunet.com>
Thu, 27 Oct 2022 14:35:12 +0000 (16:35 +0200)
commit7f57f8165cb6d2c206e2b9ada53b9e2d6d8af42f
tree854af173086b91c684f6e2998134924f206154ab
parent4b549ccce941798703f159b227aa28c716aa78fa
af_key: Fix send_acquire race with pfkey_register

The function pfkey_send_acquire may race with pfkey_register
(which could even be in a different name space).  This may result
in a buffer overrun.

Allocating the maximum amount of memory that could be used prevents
this.

Reported-by: syzbot+1e9af9185d8850e2c2fa@syzkaller.appspotmail.com
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Reviewed-by: Sabrina Dubroca <sd@queasysnail.net>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
net/key/af_key.c