]> git.kernelconcepts.de Git - karo-tx-linux.git/commit
e1000e: enhance frame fragment detection
authorJesse Brandeburg <jesse.brandeburg@intel.com>
Tue, 19 Jan 2010 14:15:59 +0000 (14:15 +0000)
committerGreg Kroah-Hartman <gregkh@suse.de>
Tue, 9 Feb 2010 12:50:45 +0000 (04:50 -0800)
commitb9ad9bb6350ddfb943e30ddd9ece9d349f7b374d
treea12e24ec0e2c08c53e20def4671d7e7833531153
parentdff2267e0c21d0d478b29bc921e8ec4f0ea462e6
e1000e: enhance frame fragment detection

commit b94b50289622e816adc9f94111cfc2679c80177c upstream.

Originally patched by Neil Horman <nhorman@tuxdriver.com>

e1000e could with a jumbo frame enabled interface, and packet split disabled,
receive a packet that would overflow a single rx buffer.  While in practice
very hard to craft a packet that could abuse this, it is possible.

this is related to CVE-2009-4538

Signed-off-by: Jesse Brandeburg <jesse.brandeburg@intel.com>
CC: Neil Horman <nhorman@tuxdriver.com>
Signed-off-by: Jeff Kirsher <jeffrey.t.kirsher@intel.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
drivers/net/e1000e/e1000.h
drivers/net/e1000e/netdev.c