Re: [PATCH] crypto: user - re-add size check for CRYPTO_MSG_GETALG

2016-06-23 Thread Herbert Xu
On Thu, Jun 23, 2016 at 04:46:26PM +0200, Stephan Mueller wrote: > > Please revert my patch eed1e1afd8d542d9644534c1b712599b5d680007 as requested > by Matthias. It's already done. Thanks. -- Email: Herbert Xu Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/

Re: [PATCH] crypto: user - re-add size check for CRYPTO_MSG_GETALG

2016-06-23 Thread Stephan Mueller
Am Donnerstag, 23. Juni 2016, 18:43:57 schrieb Herbert Xu: Hi Herbert, > On Wed, Jun 22, 2016 at 08:29:37PM +0200, Mathias Krause wrote: > > Commit 9aa867e46565 ("crypto: user - Add CRYPTO_MSG_DELRNG") > > accidentally removed the minimum size check for CRYPTO_MSG_GETALG > > netlink messages. Thi

Re: [PATCH] crypto: user - re-add size check for CRYPTO_MSG_GETALG

2016-06-23 Thread Herbert Xu
On Wed, Jun 22, 2016 at 08:29:37PM +0200, Mathias Krause wrote: > Commit 9aa867e46565 ("crypto: user - Add CRYPTO_MSG_DELRNG") > accidentally removed the minimum size check for CRYPTO_MSG_GETALG > netlink messages. This allows userland to send a truncated > CRYPTO_MSG_GETALG message as short as a n

Re: [PATCH] crypto: user - re-add size check for CRYPTO_MSG_GETALG

2016-06-22 Thread Mathias Krause
On 22 June 2016 at 21:03, Stephan Mueller wrote: > Am Mittwoch, 22. Juni 2016, 20:29:37 schrieb Mathias Krause: > > Hi Mathias, > >> Commit 9aa867e46565 ("crypto: user - Add CRYPTO_MSG_DELRNG") >> accidentally removed the minimum size check for CRYPTO_MSG_GETALG >> netlink messages. This allows us

Re: [PATCH] crypto: user - re-add size check for CRYPTO_MSG_GETALG

2016-06-22 Thread Stephan Mueller
Am Mittwoch, 22. Juni 2016, 20:29:37 schrieb Mathias Krause: Hi Mathias, > Commit 9aa867e46565 ("crypto: user - Add CRYPTO_MSG_DELRNG") > accidentally removed the minimum size check for CRYPTO_MSG_GETALG > netlink messages. This allows userland to send a truncated > CRYPTO_MSG_GETALG message as s

[PATCH] crypto: user - re-add size check for CRYPTO_MSG_GETALG

2016-06-22 Thread Mathias Krause
Commit 9aa867e46565 ("crypto: user - Add CRYPTO_MSG_DELRNG") accidentally removed the minimum size check for CRYPTO_MSG_GETALG netlink messages. This allows userland to send a truncated CRYPTO_MSG_GETALG message as short as a netlink header only making crypto_report() operate on uninitialized memor