The ipf module calculates fragment bounds with uint16_t, that can be wrapped around, causing access to invalid memory. Fix it. Other commits are supporting this fix.
v3-v2: - Added ipf: Drop overlap fragments. - Added ofproto-dpif: Use strip_recirc in reassembly dump-flows checks. - Zero-payload commit now focuses only on adding an additional byte to the test, as the new bounds commit would reject it otherwise. - Wrapping bounds - separated checks for rest_len <= 0. v4-v3: - Added 2 more commits. - Wrapping bounds - added a TOO_LARGE counter. v5-v4: - Added a test coverage for drop overlap fragments. - Fixed a wrongly counted IPv6 too-large counter. - Added BEYOND_LAST counter. v6-v5: - Overlap now drops the whole datagram. Exact duplicates are dropped alone. - Added RFC references in the code comments. Eli Britstein (6): ipf: Drop overlapping fragments and their datagram. ofproto-dpif: Use strip_recirc in reassembly dump-flows checks. ofproto-dpif: Fix reassembly test for zero-payload frags. ipf: Reject IPv4/v6 fragments with wrapping bounds. ipf: Distinguish duplicate and overlapping fragments. ipf: Reject fragments beyond the last fragment. lib/dpctl.c | 12 ++ lib/dpif-provider.h | 3 + lib/ipf.c | 210 ++++++++++++++++++--- lib/ipf.h | 3 + tests/ofproto-dpif.at | 303 ++++++++++++++++++++++++++++--- tests/system-userspace-macros.at | 24 +++ 6 files changed, 501 insertions(+), 54 deletions(-) -- 2.43.0 _______________________________________________ dev mailing list [email protected] https://mail.openvswitch.org/mailman/listinfo/ovs-dev
