HomeFreeBSD

- Use unsigned version of min() when handling arguments of SETFKEY ioctl.

Description

  • Use unsigned version of min() when handling arguments of SETFKEY ioctl.
  • Validate that user supplied control message length in sendmsg(2) is not negative.

Security: SA-16:18
Security: CVE-2016-1886
Security: SA-16:19
Security: CVE-2016-1887
Submitted by: C Turt <cturt hardenedbsd.org>
Approved by: so

Details

Provenance
glebiusAuthored on
Parents
rS300087: - Use unsigned version of min() when handling arguments of SETFKEY ioctl.
Branches
Unknown
Tags
Unknown