Page MenuHomeFreeBSD

Fix getsockopt(..., IPPROTO_IP, IP_OPTIONS, ..., ...)
ClosedPublic

Authored by tuexen on Jan 5 2019, 12:44 PM.
Tags
None
Referenced Files
Unknown Object (File)
Sun, Sep 6, 12:27 AM
Unknown Object (File)
Sat, Sep 5, 8:13 PM
Unknown Object (File)
Sat, Sep 5, 5:14 PM
Unknown Object (File)
Fri, Sep 4, 9:20 PM
Unknown Object (File)
Thu, Sep 3, 5:02 PM
Unknown Object (File)
Wed, Sep 2, 11:47 PM
Unknown Object (File)
Wed, Sep 2, 3:07 PM
Unknown Object (File)
Wed, Sep 2, 5:39 AM
Subscribers

Details

Summary

r336616 copies inp->inp_options using the m_dup() function. However, this function expects an mbuf packet header at the beginning, which is not true in this case. Therefore, use m_copym() instead of m_dup().

Test Plan

Use the attached test program to verify that getsockopt(..., IPPROTO_IP, IP_OPTIONS, ..., ...) works. Without the patch, the system panics when running the test program.

This issue what found by running syzkaller.

Diff Detail

Repository
rS FreeBSD src repository - subversion
Lint
Lint Skipped
Unit
Tests Skipped
Build Status
Buildable 21844