Skip to content

Commit 48df98d

Browse files
Raphael Zimmergregkh
authored andcommitted
libceph: Fix potential out-of-bounds access in osdmap_decode()
commit 35d0ed82d03e5ee77ea4f31f20e29562a7721649 upstream. When decoding osd_state and osd_weight from an incoming osdmap in osdmap_decode(), both are decoded for each osd, i.e., map->max_osd times. The ceph_decode_need() check only accounts for sizeof(*map->osd_weight) once. This can potentially result in an out-of-bounds memory access if the incoming message is corrupted such that the max_osd value exceeds the actual content of the osdmap message. This patch fixes the issue by changing the corresponding part in the ceph_decode_need() check to account for map->max_osd*sizeof(*map->osd_weight). Cc: stable@vger.kernel.org Fixes: dcbc919 ("libceph: switch osdmap decoding to use ceph_decode_entity_addr") Signed-off-by: Raphael Zimmer <raphael.zimmer@tu-ilmenau.de> Reviewed-by: Ilya Dryomov <idryomov@gmail.com> Signed-off-by: Ilya Dryomov <idryomov@gmail.com> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
1 parent 0de5cb2 commit 48df98d

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

net/ceph/osdmap.c

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1703,7 +1703,7 @@ static int osdmap_decode(void **p, void *end, bool msgr2,
17031703
ceph_decode_need(p, end, 3*sizeof(u32) +
17041704
map->max_osd*(struct_v >= 5 ? sizeof(u32) :
17051705
sizeof(u8)) +
1706-
sizeof(*map->osd_weight), e_inval);
1706+
map->max_osd*sizeof(*map->osd_weight), e_inval);
17071707
if (ceph_decode_32(p) != map->max_osd)
17081708
goto e_inval;
17091709

0 commit comments

Comments
 (0)