mirror of
https://github.com/Fishwaldo/Star64_linux.git
synced 2025-03-16 04:04:06 +00:00
xen-netfront: restore __skb_queue_tail() positioning in xennet_get_responses()
commitf63c2c2032
upstream. The commit referenced below moved the invocation past the "next" label, without any explanation. In fact this allows misbehaving backends undue control over the domain the frontend runs in, as earlier detected errors require the skb to not be freed (it may be retained for later processing via xennet_move_rx_slot(), or it may simply be unsafe to have it freed). This is CVE-2022-33743 / XSA-405. Fixes:6c5aa6fc4d
("xen networking: add basic XDP support for xen-netfront") Signed-off-by: Jan Beulich <jbeulich@suse.com> Reviewed-by: Juergen Gross <jgross@suse.com> Signed-off-by: Juergen Gross <jgross@suse.com> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
This commit is contained in:
parent
3e1ddddb3b
commit
7179b41bc6
1 changed files with 3 additions and 1 deletions
|
@ -1094,8 +1094,10 @@ static int xennet_get_responses(struct netfront_queue *queue,
|
|||
}
|
||||
}
|
||||
rcu_read_unlock();
|
||||
next:
|
||||
|
||||
__skb_queue_tail(list, skb);
|
||||
|
||||
next:
|
||||
if (!(rx->flags & XEN_NETRXF_more_data))
|
||||
break;
|
||||
|
||||
|
|
Loading…
Add table
Reference in a new issue