Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit 4479ff76 authored by Steffen Klassert's avatar Steffen Klassert
Browse files

xfrm: Fix replay size checking on async events



We pass the wrong netlink attribute to xfrm_replay_verify_len().
It should be XFRMA_REPLAY_ESN_VAL and not XFRMA_REPLAY_VAL as
we currently doing. This causes memory corruptions if the
replay esn attribute has incorrect length. Fix this by passing
the right attribute to xfrm_replay_verify_len().

Reported-by: default avatarMichael Rossberg <michael.rossberg@tu-ilmenau.de>
Signed-off-by: default avatarSteffen Klassert <steffen.klassert@secunet.com>
parent 73a695f8
Loading
Loading
Loading
Loading
+1 −1
Original line number Diff line number Diff line
@@ -1856,7 +1856,7 @@ static int xfrm_new_ae(struct sk_buff *skb, struct nlmsghdr *nlh,
	if (x->km.state != XFRM_STATE_VALID)
		goto out;

	err = xfrm_replay_verify_len(x->replay_esn, rp);
	err = xfrm_replay_verify_len(x->replay_esn, re);
	if (err)
		goto out;