Page MenuHomeFreeBSD

Return error code if no matching SA was found
ClosedPublic

Authored by wma on Jul 2 2021, 4:41 AM.
Tags
None
Referenced Files
Unknown Object (File)
Wed, Nov 6, 3:57 PM
Unknown Object (File)
Thu, Oct 31, 10:40 PM
Unknown Object (File)
Mon, Oct 28, 3:33 AM
Unknown Object (File)
Wed, Oct 23, 8:56 AM
Unknown Object (File)
Sun, Oct 20, 8:17 AM
Unknown Object (File)
Sun, Oct 20, 8:17 AM
Unknown Object (File)
Sun, Oct 20, 8:17 AM
Unknown Object (File)
Sun, Oct 20, 7:57 AM
Subscribers

Details

Summary

If we matched SP to a packet, but no associated SA was found
ipsec4_allocsa will return NULL while setting error=0.
This resulted in use after free and potential kernel panic.
Return EINPROGRESS if the case described above instead.

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

wma requested review of this revision.Jul 2 2021, 4:41 AM
This revision was not accepted when it landed; it landed in state Needs Review.Aug 13 2021, 7:37 AM
This revision was automatically updated to reflect the committed changes.