Re: [PATCH] lib/mpi: avoid null pointer deref in mpi_cmp_ui()

From: Herbert Xu
Date: Fri Aug 04 2023 - 05:20:34 EST


On Mon, Jul 24, 2023 at 12:07:27AM +0000, Mark O'Donovan wrote:
> During NVMeTCP Authentication a controller can trigger a kernel
> oops by specifying the 8192 bit Diffie Hellman group and passing
> a correctly sized, but zeroed Diffie Hellamn value.
> mpi_cmp_ui() was detecting this if the second parameter was 0,
> but 1 is passed from dh_is_pubkey_valid(). This causes the null
> pointer u->d to be dereferenced towards the end of mpi_cmp_ui()
>
> Signed-off-by: Mark O'Donovan <shiftee@xxxxxxxxxx>
> ---
> lib/mpi/mpi-cmp.c | 8 ++++++--
> 1 file changed, 6 insertions(+), 2 deletions(-)

Could you please resend this to linux-crypto?

Thanks,
--
Email: Herbert Xu <herbert@xxxxxxxxxxxxxxxxxxx>
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt