Commit d200cf62 authored by Christoph Hellwig's avatar Christoph Hellwig Committed by David S. Miller
Browse files

bpfilter: reject kernel addresses



The bpfilter user mode helper processes the optval address using
process_vm_readv.  Don't send it kernel addresses fed under
set_fs(KERNEL_DS) as that won't work.

Signed-off-by: default avatarChristoph Hellwig <hch@lst.de>
Signed-off-by: default avatarDavid S. Miller <davem@davemloft.net>
parent c9ffebdd
Loading
Loading
Loading
Loading
+4 −0
Original line number Diff line number Diff line
@@ -70,6 +70,10 @@ static int bpfilter_process_sockopt(struct sock *sk, int optname,
		.addr		= (uintptr_t)optval,
		.len		= optlen,
	};
	if (uaccess_kernel()) {
		pr_err("kernel access not supported\n");
		return -EFAULT;
	}
	return bpfilter_send_req(&req);
}