qubes-linux-kernel/patches.xen/xsa155-linux44-0010-xen-netfront-do-not-use-data-already-exposed-to-back.patch

65 lines
2.0 KiB
Diff
Raw Normal View History

2018-08-15 12:57:19 +00:00
From 11b753cc107f41aca56ba0698a1bd6b806cd6795 Mon Sep 17 00:00:00 2001
2015-12-17 08:24:01 +00:00
From: =?UTF-8?q?Marek=20Marczykowski-G=C3=B3recki?=
<marmarek@invisiblethingslab.com>
Date: Wed, 16 Dec 2015 05:19:37 +0100
2018-08-15 12:57:19 +00:00
Subject: [PATCH] xen-netfront: do not use data already exposed to backend
2015-12-17 08:24:01 +00:00
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Backend may freely modify anything on shared page, so use data which was
supposed to be written there, instead of reading it back from the shared
page.
This is part of XSA155.
CC: stable@vger.kernel.org
Signed-off-by: Marek Marczykowski-Górecki <marmarek@invisiblethingslab.com>
---
2018-08-15 12:57:19 +00:00
drivers/net/xen-netfront.c | 9 +++++----
1 file changed, 5 insertions(+), 4 deletions(-)
2015-12-17 08:24:01 +00:00
diff --git a/drivers/net/xen-netfront.c b/drivers/net/xen-netfront.c
2018-08-15 12:57:19 +00:00
index 1b6c319d74f1..026d39702217 100644
2015-12-17 08:24:01 +00:00
--- a/drivers/net/xen-netfront.c
+++ b/drivers/net/xen-netfront.c
2018-08-15 12:57:19 +00:00
@@ -459,7 +459,7 @@ static void xennet_tx_setup_grant(unsigned long gfn, unsigned int offset,
tx->flags = 0;
2015-12-17 08:24:01 +00:00
info->tx = tx;
- info->size += tx->size;
+ info->size += len;
}
2015-12-17 08:24:01 +00:00
static struct xen_netif_tx_request *xennet_make_first_txreq(
2018-08-15 12:57:19 +00:00
@@ -575,7 +575,7 @@ static netdev_tx_t xennet_start_xmit(struct sk_buff *skb, struct net_device *dev
2015-12-17 08:24:01 +00:00
int slots;
struct page *page;
unsigned int offset;
- unsigned int len;
+ unsigned int len, this_len;
unsigned long flags;
struct netfront_queue *queue = NULL;
unsigned int num_queues = dev->real_num_tx_queues;
2018-08-15 12:57:19 +00:00
@@ -635,14 +635,15 @@ static netdev_tx_t xennet_start_xmit(struct sk_buff *skb, struct net_device *dev
2015-12-17 08:24:01 +00:00
}
/* First request for the linear area. */
+ this_len = min_t(unsigned int, XEN_PAGE_SIZE - offset, len);
first_tx = tx = xennet_make_first_txreq(queue, skb,
page, offset, len);
- offset += tx->size;
+ offset += this_len;
if (offset == PAGE_SIZE) {
page++;
offset = 0;
}
2015-12-17 08:24:01 +00:00
- len -= tx->size;
+ len -= this_len;
if (skb->ip_summed == CHECKSUM_PARTIAL)
/* local packet? */
2018-08-15 12:57:19 +00:00
--
2.17.1