summaryrefslogtreecommitdiff
path: root/net/ipv4
diff options
context:
space:
mode:
authorZijie Huang <milkory@outlook.com>2026-09-21 01:36:19 +0800
committerJakub Kicinski <kuba@kernel.org>2026-09-23 19:00:15 -0700
commitd8b6529e80bcb4fb8177121404cbb3377acaebd2 (patch)
tree9af57aadd912232698d919ff7721e955ad75ccf8 /net/ipv4
parent89a8a1eef2d441b7825a6c0116ce817235a7ffe6 (diff)
net: arp: terminate device name before lookup
The ARP ioctl copies a user-provided struct arpreq into a stack object. Its arp_dev field may contain IFNAMSIZ bytes without a NUL terminator. Such input is passed to dev_get_by_name_rcu() or __dev_get_by_name(), where strcmp() can read past the end of the stack object when a matching alternative interface name exists. Terminate the field before the lookup to prevent the out-of-bounds read. Fixes: 36fbf1e52bd3 ("net: rtnetlink: add linkprop commands to add and delete alternative ifnames") Cc: stable@vger.kernel.org Reported-by: Vega <vega@nebusec.ai> Signed-off-by: Zijie Huang <milkory@outlook.com> Signed-off-by: Ren Wei <weir@nebusec.ai> Reviewed-by: Ido Schimmel <idosch@nvidia.com> Link: https://patch.msgid.link/fabf02a70787d17299e4b3153eadffaf20d154b3.1789910973.git.milkory@outlook.com Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Diffstat (limited to 'net/ipv4')
-rw-r--r--net/ipv4/arp.c1
1 files changed, 1 insertions, 0 deletions
diff --git a/net/ipv4/arp.c b/net/ipv4/arp.c
index d409f606aec0..60009d92e071 100644
--- a/net/ipv4/arp.c
+++ b/net/ipv4/arp.c
@@ -1278,6 +1278,7 @@ int arp_ioctl(struct net *net, unsigned int cmd, void __user *arg)
err = copy_from_user(&r, arg, sizeof(struct arpreq));
if (err)
return -EFAULT;
+ r.arp_dev[IFNAMSIZ - 1] = '\0';
break;
default:
return -EINVAL;