From: Pablo Neira Ayuso Date: Tue, 6 Jun 2023 14:32:44 +0000 (+0200) Subject: netfilter: nf_tables: out-of-bound check in chain blob X-Git-Tag: v6.1.37~468 X-Git-Url: http://review.tizen.org/git/?a=commitdiff_plain;h=65f2def2066255eb9ee6cbfe2961ed09e913ea9b;p=platform%2Fkernel%2Flinux-starfive.git netfilter: nf_tables: out-of-bound check in chain blob [ Upstream commit 08e42a0d3ad30f276f9597b591f975971a1b0fcf ] Add current size of rule expressions to the boundary check. Fixes: 2c865a8a28a1 ("netfilter: nf_tables: add rule blob layout") Signed-off-by: Pablo Neira Ayuso Signed-off-by: Sasha Levin --- diff --git a/net/netfilter/nf_tables_api.c b/net/netfilter/nf_tables_api.c index 31775d5..437891c 100644 --- a/net/netfilter/nf_tables_api.c +++ b/net/netfilter/nf_tables_api.c @@ -8723,7 +8723,7 @@ static int nf_tables_commit_chain_prepare(struct net *net, struct nft_chain *cha continue; } - if (WARN_ON_ONCE(data + expr->ops->size > data_boundary)) + if (WARN_ON_ONCE(data + size + expr->ops->size > data_boundary)) return -ENOMEM; memcpy(data + size, expr, expr->ops->size);