Page MenuHomeFreeBSD

ip6_output(): Check the return value of in6_getlinkifnet().
ClosedPublic

Authored by markj on Thu, Jul 30, 12:46 AM.

Details

Summary

If the destination address has an embedded scope ID, make sure that it
corresponds to a valid ifnet before proceeding. Otherwise a sendto()
with a bogus link-local address can trigger a NULL pointer dereference.

Reported by: syzkaller

Diff Detail

Repository
rS FreeBSD src repository
Lint
Automatic diff as part of commit; lint not applicable.
Unit
Automatic diff as part of commit; unit tests not applicable.

Event Timeline

markj created this revision.Thu, Jul 30, 12:46 AM
markj requested review of this revision.Thu, Jul 30, 12:46 AM
ae accepted this revision.Thu, Jul 30, 7:45 AM

LGTM.

This revision is now accepted and ready to land.Thu, Jul 30, 7:45 AM
This revision was automatically updated to reflect the committed changes.