Nixpkgs security tracker

Try the new UI
Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Suggestion detail

Dismissed
(max. allowed matches exceeded)
created 1 week, 6 days ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header

In the Linux kernel, the following vulnerability has been resolved: net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header dev_validate_header() reads dev->hard_header_len directly when zero-padding short link layer headers for CAP_SYS_RAWIO holders: if (capable(CAP_SYS_RAWIO)) { memset(ll_header + len, 0, dev->hard_header_len - len); return true; } Packet send paths call dev_validate_header() on skbs whose headroom was allocated from an earlier hard_header_len read. If the device is reconfigured so that dev->hard_header_len increases before validation, the memset writes past the reserved buffer, an out-of-bounds write. This out-of-bounds write is masked in some SOCK_RAW paths today because the same concurrent increase can first make skb_push() exceed the reserved headroom and trigger skb_under_panic(). Remove the zero-padding branch before making those hard_header_len reads consistent, so the snapshot fixes do not turn a loud panic into a silent overwrite. This path is only reached for variable length L2 protocols, where len < hard_header_len but len >= min_header_len. No remaining in-tree variable length L2 protocol implements header_ops->validate, and the CAP_SYS_RAWIO bypass that zero-pads and accepts short headers has no real value beyond allowing testing of intentionally malformed input. Drop the CAP_SYS_RAWIO branch. The remaining reads of dev->hard_header_len in dev_validate_header() are comparisons only and have no memory safety impact.

Affected products

Linux
  • <b0f92a5731dc82556a9ae005cc35f71ab136307b
  • =<*
  • <4.5
  • <53fd7f912c0877647d6a1e1877f5ea8535ee0b4a
  • ==6804052fa9d86e9a512c88b24a5debbfc1a490fc
  • <fa6d98dd925e72fc028b26a0cbbff9d2f0601ff6
  • ==f58a6c08ebdfa978178bbca78c2ba744a2665912
  • <dbb30dc943a93e083f1e531bfdc6779e57de40d0
  • <3.2.81
  • =<6.1.*
  • <4.2
  • <3b9a324e646d3657a8d9806dfbfe4f3e4066e882
  • =<6.12.*
  • =<6.6.*
  • <99df6b7a713f96eda206680d100b76e15f9d9b69
  • <4.6
  • =<5.10.*
  • =<7.1.*
  • =<6.18.*
  • <fc902f52a02298c7432b2334c0c82a2885a1a8b6
  • <4.6
  • =<5.15.*
  • ==8b8d278aa4de9335682bbd4a3bb619af015c859e
  • =<3.2.*
  • <3.17
  • <8fc9816404166a90ed8d544dc52482fafffb6d9f
  • ==1df16498dfd0d5a129bdf2982d9a08df73e8923d
  • ==4.6
  • <74e035f07f53feca09e2352e77fccb09cad5e208