Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit 3179dd79 authored by Haimin Zhang's avatar Haimin Zhang Committed by Greg Kroah-Hartman
Browse files

fix array-index-out-of-bounds in taprio_change



[ Upstream commit efe487fce3061d94222c6501d7be3aa549b3dc78 ]

syzbot report an array-index-out-of-bounds in taprio_change
index 16 is out of range for type '__u16 [16]'
that's because mqprio->num_tc is lager than TC_MAX_QUEUE,so we check
the return value of netdev_set_num_tc.

Reported-by: default avatar <syzbot+2b3e5fb6c7ef285a94f6@syzkaller.appspotmail.com>
Signed-off-by: default avatarHaimin Zhang <tcs_kernel@tencent.com>
Signed-off-by: default avatarDavid S. Miller <davem@davemloft.net>
Signed-off-by: default avatarSasha Levin <sashal@kernel.org>
parent ef9a7867
Loading
Loading
Loading
Loading
+3 −1
Original line number Diff line number Diff line
@@ -1503,7 +1503,9 @@ static int taprio_change(struct Qdisc *sch, struct nlattr *opt,
	taprio_set_picos_per_byte(dev, q);

	if (mqprio) {
		netdev_set_num_tc(dev, mqprio->num_tc);
		err = netdev_set_num_tc(dev, mqprio->num_tc);
		if (err)
			goto free_sched;
		for (i = 0; i < mqprio->num_tc; i++)
			netdev_set_tc_queue(dev, i,
					    mqprio->count[i],