]> git.karo-electronics.de Git - karo-tx-linux.git/commit
TCP: Make sure write_queue_from does not begin with NULL ptr (CVE-2007-5501)
authorIlpo Järvinen <ilpo.jarvinen@helsinki.fi>
Wed, 14 Nov 2007 23:47:18 +0000 (15:47 -0800)
committerGreg Kroah-Hartman <gregkh@suse.de>
Fri, 16 Nov 2007 18:26:42 +0000 (10:26 -0800)
commit1ca9e250e9f8675dc1db7fcd1cee8c0bf0bfc071
tree54a318d68306063ffca50510ec4c5339a5f2edc2
parent5ef016ad9ba96a77a7249a2bd8d3196af5bfd920
TCP: Make sure write_queue_from does not begin with NULL ptr (CVE-2007-5501)

patch 96a2d41a3e495734b63bff4e5dd0112741b93b38 in mainline.

NULL ptr can be returned from tcp_write_queue_head to cached_skb
and then assigned to skb if packets_out was zero. Without this,
system is vulnerable to a carefully crafted ACKs which obviously
is remotely triggerable.

Besides, there's very little that needs to be done in sacktag
if there weren't any packets outstanding, just skipping the rest
doesn't hurt.

Signed-off-by: Ilpo Järvinen <ilpo.jarvinen@helsinki.fi>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
net/ipv4/tcp_input.c