HomeFreeBSD

netmap: Fix TOCTOU vulnerability in nmreq_copyin

Description

netmap: Fix TOCTOU vulnerability in nmreq_copyin

The total size of the user-provided nmreq was first computed and then
trusted during the copyin. This might lead to kernel memory corruption
and escape from jails/containers.

Reported by: Lucas Leong (@_wmliang_) of Trend Micro Zero Day Initiative
Security: CVE-2022-23084
MFC after: 3 days

(cherry picked from commit 393729916564ed13f966e09129a24e6931898d12)

Details

Provenance
vmaffioneAuthored on Mar 16 2022, 6:58 AM
Parents
rG9df8dd3ea36c: netmap: Fix integer overflow in nmreq_copyin
Branches
Unknown
Tags
Unknown