Andy Whitcroft f843ee6dd0 xfrm_user: validate XFRM_MSG_NEWAE incoming ESN size harder
Kees Cook has pointed out that xfrm_replay_state_esn_len() is subject to
wrapping issues.  To ensure we are correctly ensuring that the two ESN
structures are the same size compare both the overall size as reported
by xfrm_replay_state_esn_len() and the internal length are the same.

CVE-2017-7184
Signed-off-by: Andy Whitcroft <apw@canonical.com>
Acked-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
2017-03-29 08:40:15 -07:00
..
2016-12-03 23:54:25 -05:00
2017-02-14 22:19:39 -05:00
2016-12-25 17:21:22 +01:00
2017-02-10 15:57:34 -05:00
2016-10-20 11:23:08 -04:00
2016-12-20 14:22:49 -05:00
2016-08-17 19:36:23 -04:00