diff options
| author | Ben Pfaff <blp@nicira.com> | 2011-02-01 11:23:30 -0800 |
|---|---|---|
| committer | Ben Pfaff <blp@nicira.com> | 2011-02-03 14:55:28 -0800 |
| commit | 535d6987a7af3bef33bf2db21b52bb81e3ea64ee (patch) | |
| tree | b5bcaca920c06c1597b47880760b1c8fa474b5c8 /datapath | |
| parent | 87824b0bfa2daf4a1b1949a96feaeb0d5710fb38 (diff) | |
| download | openvswitch-535d6987a7af3bef33bf2db21b52bb81e3ea64ee.tar.gz | |
Zero padding bytes in odp_key_ipv4, odp_key_arp.
This is a potential security issue for the kernel. In userspace it just
provokes false-positive valgrind warnings (which is how I found it).
Signed-off-by: Ben Pfaff <blp@nicira.com>
Acked-by: Jesse Gross <jesse@nicira.com>
Diffstat (limited to 'datapath')
| -rw-r--r-- | datapath/flow.c | 3 |
1 files changed, 3 insertions, 0 deletions
diff --git a/datapath/flow.c b/datapath/flow.c index 9823b9feb..735e14795 100644 --- a/datapath/flow.c +++ b/datapath/flow.c @@ -845,6 +845,7 @@ int flow_to_nlattrs(const struct sw_flow_key *swkey, struct sk_buff *skb) if (!nla) goto nla_put_failure; ipv4_key = nla_data(nla); + memset(ipv4_key, 0, sizeof(struct odp_key_ipv4)); ipv4_key->ipv4_src = swkey->ipv4_src; ipv4_key->ipv4_dst = swkey->ipv4_dst; ipv4_key->ipv4_proto = swkey->nw_proto; @@ -856,6 +857,7 @@ int flow_to_nlattrs(const struct sw_flow_key *swkey, struct sk_buff *skb) if (!nla) goto nla_put_failure; ipv6_key = nla_data(nla); + memset(ipv6_key, 0, sizeof(struct odp_key_ipv6)); memcpy(ipv6_key->ipv6_src, swkey->ipv6_src, sizeof(ipv6_key->ipv6_src)); memcpy(ipv6_key->ipv6_dst, swkey->ipv6_dst, @@ -869,6 +871,7 @@ int flow_to_nlattrs(const struct sw_flow_key *swkey, struct sk_buff *skb) if (!nla) goto nla_put_failure; arp_key = nla_data(nla); + memset(arp_key, 0, sizeof(struct odp_key_arp)); arp_key->arp_sip = swkey->ipv4_src; arp_key->arp_tip = swkey->ipv4_dst; arp_key->arp_op = htons(swkey->nw_proto); |
