Page MenuHomeFreeBSD

Fix getsockopt(..., IPPROTO_IP, IP_OPTIONS, ..., ...)
ClosedPublic

Authored by tuexen on Jan 5 2019, 12:44 PM.
Tags
None
Referenced Files
Unknown Object (File)
Sat, Aug 1, 1:08 PM
Unknown Object (File)
Fri, Jul 31, 1:42 AM
Unknown Object (File)
Thu, Jul 30, 5:19 PM
Unknown Object (File)
Tue, Jul 28, 11:29 PM
Unknown Object (File)
Sun, Jul 26, 6:08 PM
Unknown Object (File)
Tue, Jul 21, 9:01 AM
Unknown Object (File)
Sat, Jul 18, 8:34 AM
Unknown Object (File)
Wed, Jul 8, 5:06 AM
Subscribers

Details

Summary

r336616 copies inp->inp_options using the m_dup() function. However, this function expects an mbuf packet header at the beginning, which is not true in this case. Therefore, use m_copym() instead of m_dup().

Test Plan

Use the attached test program to verify that getsockopt(..., IPPROTO_IP, IP_OPTIONS, ..., ...) works. Without the patch, the system panics when running the test program.

This issue what found by running syzkaller.

Diff Detail

Repository
rS FreeBSD src repository - subversion
Lint
Lint Not Applicable
Unit
Tests Not Applicable