]> CyberLeo.Net >> Repos - FreeBSD/FreeBSD.git/commit
accept_filter: Fix filter parameter handling
authorMark Johnston <markj@FreeBSD.org>
Thu, 25 Mar 2021 21:55:20 +0000 (17:55 -0400)
committerMark Johnston <markj@FreeBSD.org>
Thu, 25 Mar 2021 21:55:46 +0000 (17:55 -0400)
commit653a437c04440495cd8e7712c7cf39444f26f1ee
tree295974747102395149269a2a094dd3c5d87a61ad
parent15f33555678300953858f6ed98dfc72c399a9139
accept_filter: Fix filter parameter handling

For filters which implement accf_create, the setsockopt(2) handler
caches the filter name in the socket, but it also incorrectly frees the
buffer containing the copy, leaving a dangling pointer.  Note that no
accept filters provided in the base system are susceptible to this, as
they don't implement accf_create.

Reported by: Alexey Kulaev <alex.qart@gmail.com>
Discussed with: emaste
Security: kernel use-after-free
MFC after: 3 days
Sponsored by: The FreeBSD Foundation
sys/kern/uipc_accf.c