From: Kangjie Lu Date: Thu, 2 Jun 2016 08:11:20 +0000 (-0400) Subject: rds: fix an infoleak in rds_inc_info_copy X-Git-Tag: v3.2.82~3 X-Git-Url: https://git.openpandora.org/cgi-bin/gitweb.cgi?p=pandora-kernel.git;a=commitdiff_plain;h=948969a457e89903d180d01cbcbfee59c16f5bb5 rds: fix an infoleak in rds_inc_info_copy commit 4116def2337991b39919f3b448326e21c40e0dbb upstream. The last field "flags" of object "minfo" is not initialized. Copying this object out may leak kernel stack data. Assign 0 to it to avoid leak. Signed-off-by: Kangjie Lu Acked-by: Santosh Shilimkar Signed-off-by: David S. Miller Signed-off-by: Ben Hutchings --- diff --git a/net/rds/recv.c b/net/rds/recv.c index 96a1239c05c2..9e28c993584a 100644 --- a/net/rds/recv.c +++ b/net/rds/recv.c @@ -544,5 +544,7 @@ void rds_inc_info_copy(struct rds_incoming *inc, minfo.fport = inc->i_hdr.h_dport; } + minfo.flags = 0; + rds_info_copy(iter, &minfo, sizeof(minfo)); }