]> git.dujemihanovic.xyz Git - u-boot.git/commit
CVE: net: fix unbounded memcpy of UDP packet
authorliucheng (G) <liucheng32@huawei.com>
Thu, 29 Aug 2019 13:47:33 +0000 (13:47 +0000)
committerJoe Hershberger <joe.hershberger@ni.com>
Wed, 4 Sep 2019 16:37:19 +0000 (11:37 -0500)
commitfe7288069d2e6659117049f7d27e261b550bb725
treec68947cedb27841b166023d3a68377056f1a4db2
parent12c2a310e87d4eacfd669346338e856cb3ad54c2
CVE: net: fix unbounded memcpy of UDP packet

This patch adds a check to udp_len to fix unbounded memcpy for
CVE-2019-14192, CVE-2019-14193 and CVE-2019-14199.

Signed-off-by: Cheng Liu <liucheng32@huawei.com>
Reviewed-by: Simon Goldschmidt <simon.k.r.goldschmidt@gmail.com>
Reported-by: Fermín Serna <fermin@semmle.com>
Acked-by: Joe Hershberger <joe.hershberger@ni.com>
net/net.c