tree f53f0571d05cb541b37569315e72ba4341462c95
parent bd53fbdd7ef7edbb36e04ffb451b0aa3fa97ca8c
author Marcelo Ricardo Leitner <marcelo.leitner@gmail.com> 1624907621 -0300
committer Karsten Tausche <karsten@fairphone.com> 1648458789 +0200

sctp: validate from_addr_param return

commit 0c5dc070ff3d6246d22ddd931f23a6266249e3db upstream.

Ilja reported that, simply putting it, nothing was validating that
from_addr_param functions were operating on initialized memory. That is,
the parameter itself was being validated by sctp_walk_params, but it
doesn't check for types and their specific sizes and it could be a 0-length
one, causing from_addr_param to potentially work over the next parameter or
even uninitialized memory.

The fix here is to, in all calls to from_addr_param, check if enough space
is there for the wanted IP address type.

Reported-by: Ilja Van Sprundel <ivansprundel@ioactive.com>
Signed-off-by: Marcelo Ricardo Leitner <marcelo.leitner@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Change-Id: I7c84e42afa19aa569885a676af27e33999b76430
Issue: FP3SEC-257
(cherry picked from commit 92e7bca98452aa760713016a434aa7edfc09fb13)
