On 2/17/21 2:47 AM, William Tu wrote:
> On Tue, Feb 16, 2021 at 2:27 PM Ilya Maximets <[email protected]> wrote:
>>
>> While decoding RAW_ENCAP action, decode_ed_prop() might re-allocate
>> ofpbuf if there is no enough space left.  However, function
>> 'decode_NXAST_RAW_ENCAP' continues to use old pointer to 'encap'
>> structure leading to write-after-free and incorrect decoding.
>>
>>   ==3549105==ERROR: AddressSanitizer: heap-use-after-free on address
>>   0x60600000011a at pc 0x0000005f6cc6 bp 0x7ffc3a2d4410 sp 0x7ffc3a2d4408
>>   WRITE of size 2 at 0x60600000011a thread T0
>>     #0 0x5f6cc5 in decode_NXAST_RAW_ENCAP lib/ofp-actions.c:4461:20
>>     #1 0x5f0551 in ofpact_decode ./lib/ofp-actions.inc2:4777:16
>>     #2 0x5ed17c in ofpacts_decode lib/ofp-actions.c:7752:21
>>     #3 0x5eba9a in ofpacts_pull_openflow_actions__ lib/ofp-actions.c:7791:13
>>     #4 0x5eb9fc in ofpacts_pull_openflow_actions lib/ofp-actions.c:7835:12
>>     #5 0x64bb8b in ofputil_decode_packet_out lib/ofp-packet.c:1113:17
>>     #6 0x65b6f4 in ofp_print_packet_out lib/ofp-print.c:148:13
>>     #7 0x659e3f in ofp_to_string__ lib/ofp-print.c:1029:16
>>     #8 0x659b24 in ofp_to_string lib/ofp-print.c:1244:21
>>     #9 0x65a28c in ofp_print lib/ofp-print.c:1288:28
>>     #10 0x540d11 in ofctl_ofp_parse utilities/ovs-ofctl.c:2814:9
>>     #11 0x564228 in ovs_cmdl_run_command__ lib/command-line.c:247:17
>>     #12 0x56408a in ovs_cmdl_run_command lib/command-line.c:278:5
>>     #13 0x5391ae in main utilities/ovs-ofctl.c:179:9
>>     #14 0x7f6911ce9081 in __libc_start_main (/lib64/libc.so.6+0x27081)
>>     #15 0x461fed in _start (utilities/ovs-ofctl+0x461fed)
>>
>> Fix that by getting a new pointer before using.
>>
>> Credit to OSS-Fuzz.
>>
>> Fuzzer regression test will fail only with AddressSanitizer enabled.
>>
>> Reported-at: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=27851
>> Fixes: f839892a206a ("OF support and translation of generic encap and decap")
>> Signed-off-by: Ilya Maximets <[email protected]>
> 
> 
> LGTM.
> Acked-by: William Tu <[email protected]>
> 

Thanks!
Applied to master and backported down to 2.11.

Patch doesn't apply cleanly to older branches, so I didn't backport it there.

Best regards, Ilya Maximets.
_______________________________________________
dev mailing list
[email protected]
https://mail.openvswitch.org/mailman/listinfo/ovs-dev

Reply via email to