From patchwork Mon Dec 2 04:52:28 2019 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Po-Hsu Lin X-Patchwork-Id: 1202928 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@bilbo.ozlabs.org Authentication-Results: ozlabs.org; spf=none (no SPF record) smtp.mailfrom=lists.ubuntu.com (client-ip=91.189.94.19; helo=huckleberry.canonical.com; envelope-from=kernel-team-bounces@lists.ubuntu.com; receiver=) Authentication-Results: ozlabs.org; dmarc=fail (p=none dis=none) header.from=canonical.com Received: from huckleberry.canonical.com (huckleberry.canonical.com [91.189.94.19]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 47RCRM1zNxz9sPL; Mon, 2 Dec 2019 15:53:03 +1100 (AEDT) Received: from localhost ([127.0.0.1] helo=huckleberry.canonical.com) by huckleberry.canonical.com with esmtp (Exim 4.86_2) (envelope-from ) id 1ibdhj-0003mO-QF; Mon, 02 Dec 2019 04:52:59 +0000 Received: from youngberry.canonical.com ([91.189.89.112]) by huckleberry.canonical.com with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.86_2) (envelope-from ) id 1ibdhh-0003lQ-Je for kernel-team@lists.ubuntu.com; Mon, 02 Dec 2019 04:52:57 +0000 Received: from mail-pl1-f200.google.com ([209.85.214.200]) by youngberry.canonical.com with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.86_2) (envelope-from ) id 1ibdhh-00056F-AP for kernel-team@lists.ubuntu.com; Mon, 02 Dec 2019 04:52:57 +0000 Received: by mail-pl1-f200.google.com with SMTP id d24so4708757pll.14 for ; Sun, 01 Dec 2019 20:52:57 -0800 (PST) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:subject:date:message-id:in-reply-to :references; bh=ycoOHQG4QLENOBJFk/5pAI/QF6NoMistvfpStgAeBcM=; b=pPH6ZBatukXUbVd9KjYa2fs1lh04ZUB63osCfMoIrfP5sQsupr700f3jGSDK/0UxbY 0JDcWhSXQjjEZkAqcoN6RAxzDXGgXNFCobUo/07L5uln1gkWjVAdtaHElDUpn+LSpqXi afpsoPv2aNiTneine/gnpDhhDFrKidcBPP123U2q7PjxO1zU/FR5nj6LJ+u2fptiUkSs 4DkQB+B4bEtsAA3MpX3WDmu1cm6tmIkq2zFqBM5QXp0sqzlm8JuHp8MW/yPN7lTkBq18 I7MxML8z5ljH/GN0iLGhhspz+TsFanQTAp811euRKSRGJS7bLaZGiCqFrczESZLLUiq2 FiJw== X-Gm-Message-State: APjAAAUYTsY/Oo7oXA3j8DUds6maLR7lcRcHMOrzi6pW+P9PcOQx9aiH KmZZkieTibwQRWHDwauJ0RX3U+1NRndQggkoT2AAHpNbMUnGTFFQyoPUOYXKKFBqSyO7UtCE/p2 zhHI2VaV4iThDAUY1K39/niS6j//7nHMAqWDdkNya X-Received: by 2002:a63:8eca:: with SMTP id k193mr29298690pge.293.1575262375748; Sun, 01 Dec 2019 20:52:55 -0800 (PST) X-Google-Smtp-Source: APXvYqz21zBe7sO4Dita+5JWwTivqox7JVshok4g5UYs8DIYJWQ5OcnOyRllAsk/RGAZba3C4m3A7A== X-Received: by 2002:a63:8eca:: with SMTP id k193mr29298679pge.293.1575262375376; Sun, 01 Dec 2019 20:52:55 -0800 (PST) Received: from Leggiero.taipei.internal (61-220-137-37.HINET-IP.hinet.net. [61.220.137.37]) by smtp.gmail.com with ESMTPSA id z10sm31514257pgg.39.2019.12.01.20.52.54 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 01 Dec 2019 20:52:54 -0800 (PST) From: Po-Hsu Lin To: kernel-team@lists.ubuntu.com Subject: [D][E][F][SRU][CVE-2019-19050][PATCH 1/1] crypto: user - fix memory leak in crypto_reportstat Date: Mon, 2 Dec 2019 12:52:28 +0800 Message-Id: <20191202045228.22028-2-po-hsu.lin@canonical.com> X-Mailer: git-send-email 2.17.1 In-Reply-To: <20191202045228.22028-1-po-hsu.lin@canonical.com> References: <20191202045228.22028-1-po-hsu.lin@canonical.com> X-BeenThere: kernel-team@lists.ubuntu.com X-Mailman-Version: 2.1.20 Precedence: list List-Id: Kernel team discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , MIME-Version: 1.0 Errors-To: kernel-team-bounces@lists.ubuntu.com Sender: "kernel-team" From: Navid Emamdoost CVE-2019-19050 In crypto_reportstat, a new skb is created by nlmsg_new(). This skb is leaked if crypto_reportstat_alg() fails. Required release for skb is added. Fixes: cac5818c25d0 ("crypto: user - Implement a generic crypto statistics") Cc: Signed-off-by: Navid Emamdoost Signed-off-by: Herbert Xu (cherry picked from commit c03b04dcdba1da39903e23cc4d072abf8f68f2dd) Signed-off-by: Po-Hsu Lin Acked-by: Connor Kuehl --- crypto/crypto_user_stat.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/crypto/crypto_user_stat.c b/crypto/crypto_user_stat.c index 3e9a53233d80..0c0cb9d19591 100644 --- a/crypto/crypto_user_stat.c +++ b/crypto/crypto_user_stat.c @@ -330,8 +330,10 @@ int crypto_reportstat(struct sk_buff *in_skb, struct nlmsghdr *in_nlh, drop_alg: crypto_mod_put(alg); - if (err) + if (err) { + kfree_skb(skb); return err; + } return nlmsg_unicast(crypto_nlsk, skb, NETLINK_CB(in_skb).portid); }