diff options
| author | Mark Johnston <markj@FreeBSD.org> | 2026-09-29 18:50:02 +0000 |
|---|---|---|
| committer | Mark Johnston <markj@FreeBSD.org> | 2026-09-29 18:50:02 +0000 |
| commit | 10729d0ce11c9ac5077d158bb372f9c39053f168 (patch) | |
| tree | aea71d5fb3b088662f726c5144d6575aea93cbd6 /contrib/diff/lib/prepargs.h | |
| parent | 2127135a22e3f9eafa4ba4ca819d4971b6e27125 (diff) | |
The SIOCADDMULTI and SIOCDELMULTI handlers add or delete a link-layer
multicast address from an interface's multicast filter list. The
link-layer address is passed using the ifr_addr field of the request
structure.
struct ifreq's ifr_addr field is a struct sockaddr, which is a fair bit
smaller than struct sockaddr_dl (though big enough to hold an ethernet
address). Existing callers set the sockaddr length to
sizeof(struct sockaddr_dl), which is too large, and causes OOB accesses
when if_findmulti() is used to compare the address with others, or when
if_addmulti() makes a copy.
Fix this without breaking compatibility: copy the user-supplied address
into a sockaddr_dl on the stack, and use the latter for the respective
operation.
Also validate the sockaddr_dl internal length fields, suggested by zlei.
Reported by: Yuxiang Yang, Yizhou Zhao, Ao Wang, Xuewei Feng, Qi Li,
and Ke Xu from Tsinghua University using GLM-5.2 from Z.ai
Reviewed by: zlei, ae, glebius
MFC after: 1 week
Sponsored by: The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D59919
Diffstat (limited to 'contrib/diff/lib/prepargs.h')
0 files changed, 0 insertions, 0 deletions
