summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorMaxim Petrov <mmrmaximuzz@gmail.com>2021-11-17 22:11:24 +0300
committerStephen Hemminger <stephen@networkplumber.org>2021-11-18 15:01:48 -0800
commit5f8bb902e14f91161f9ed214d5fc1d813af8ed88 (patch)
treebac50b99f87a50b2440deafa43c029f54cdfcc84
parent3184de37976c252a217f53953a439012363d8a6f (diff)
ip/ipnexthop: fix unsigned overflow in parse_nh_group_type_res()
0UL has type 'unsigned long' which is likely to be 64bit on modern machines. At the same time, the '{idle,unbalanced}_timer' variables are declared as u32, so these variables cannot be greater than '~0UL / 100' when 'unsigned long' is 64 bits. In such condition it is still possible to pass the check but get the overflow later when the timers are multiplied by 100 in 'addattr32'. Fix the possible overflow by changing '~0UL' to 'UINT32_MAX'. Fixes: 91676718228b ("nexthop: Add support for resilient nexthop groups") Signed-off-by: Maxim Petrov <mmrmaximuzz@gmail.com> Reviewed-by: Ido Schimmel <idosch@nvidia.com> Signed-off-by: Stephen Hemminger <stephen@networkplumber.org>
-rw-r--r--ip/ipnexthop.c5
1 files changed, 3 insertions, 2 deletions
diff --git a/ip/ipnexthop.c b/ip/ipnexthop.c
index 83a5540e..2f448449 100644
--- a/ip/ipnexthop.c
+++ b/ip/ipnexthop.c
@@ -6,6 +6,7 @@
*/
#include <linux/nexthop.h>
+#include <stdint.h>
#include <stdio.h>
#include <string.h>
#include <rt_names.h>
@@ -840,7 +841,7 @@ static void parse_nh_group_type_res(struct nlmsghdr *n, int maxlen, int *argcp,
NEXT_ARG();
if (get_unsigned(&idle_timer, *argv, 0) ||
- idle_timer >= ~0UL / 100)
+ idle_timer >= UINT32_MAX / 100)
invarg("invalid idle timer value", *argv);
addattr32(n, maxlen, NHA_RES_GROUP_IDLE_TIMER,
@@ -850,7 +851,7 @@ static void parse_nh_group_type_res(struct nlmsghdr *n, int maxlen, int *argcp,
NEXT_ARG();
if (get_unsigned(&unbalanced_timer, *argv, 0) ||
- unbalanced_timer >= ~0UL / 100)
+ unbalanced_timer >= UINT32_MAX / 100)
invarg("invalid unbalanced timer value", *argv);
addattr32(n, maxlen, NHA_RES_GROUP_UNBALANCED_TIMER,