This service will be undergoing maintenance at 00:00 UTC, 2017-10-23 It is expected to last about 30 minutes
Bug 484977 - [IPV6]: Check length of optval provided by user in setsockopt()
[IPV6]: Check length of optval provided by user in setsockopt()
Status: CLOSED ERRATA
Product: Red Hat Enterprise Linux 5
Classification: Red Hat
Component: kernel (Show other bugs)
5.3
All Linux
medium Severity medium
: rc
: ---
Assigned To: Jiri Pirko
Red Hat Kernel QE team
:
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2009-02-10 17:23 EST by Dave Maley
Modified: 2015-05-04 21:16 EDT (History)
10 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2009-09-02 04:49:13 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
reproducer (1.08 KB, text/plain)
2009-02-10 17:25 EST, Dave Maley
no flags Details
patch provided by partner (383 bytes, patch)
2009-02-10 17:27 EST, Dave Maley
no flags Details | Diff

  None (edit)
Description Dave Maley 2009-02-10 17:23:39 EST
Description of problem:
when using setsockopt() with option 'IPV6_JOIN_GROUP' or 'IPV6_LEAVE_GROUP' but optlen is set to less than the length of struct 'ipv6_mreq', kernel should return error 'EINVAL' rather than 'ENODEV'.


Version-Release number of selected component (if applicable):
kernel-2.6.18-128.EL


How reproducible:
every time


Steps to Reproduce:
(see attached reproducer)
1. # gcc -o sockopt-16-17 sockopt-16-17.c
2. # ./sockopt-16-17
3.
  

Actual results:
Kernel return 'ENODEV'.

Reproduce program log.
      # ./sockopt-16-17
      == create an IPv6 socket ==
      == join to a multicast group with bad paramter ==
      ERROR: returned error 19 is not EINVAL
      <=====NG=====>


Expected results:
Kernel return 'EINVAL'


Additional info:
The reproduction program:
   sockopt-16-17.c

The patch file is attached:
   file: net-fix-return-value-when-join-or-leave-multicast-group.patch

This patch has already been applied for the Community's kernel.
Comment 1 Dave Maley 2009-02-10 17:25:45 EST
Created attachment 331489 [details]
reproducer

# gcc -o sockopt-16-17 sockopt-16-17.c
# ./sockopt-16-17
Comment 2 Dave Maley 2009-02-10 17:27:39 EST
Created attachment 331490 [details]
patch provided by partner

upstream info:
commit a28398ba6112be28c6a92aacf06aca1979b454b7
Author: Wang Chen <wangchen@cn.fujitsu.com>
Date:   Mon Apr 7 09:42:07 2008 +0800
Comment 5 RHEL Product and Program Management 2009-02-16 10:33:58 EST
Updating PM score.
Comment 6 RHEL Product and Program Management 2009-02-27 09:26:46 EST
This request was evaluated by Red Hat Product Management for inclusion in a Red
Hat Enterprise Linux maintenance release.  Product Management has requested
further review of this request by Red Hat Engineering, for potential
inclusion in a Red Hat Enterprise Linux Update release for currently deployed
products.  This request is not yet committed for inclusion in an Update
release.
Comment 7 Don Zickus 2009-03-04 15:02:19 EST
in kernel-2.6.18-133.el5
You can download this test kernel from http://people.redhat.com/dzickus/el5

Please do NOT transition this bugzilla state to VERIFIED until our QE team
has sent specific instructions indicating when to do so.  However feel free
to provide a comment indicating that this fix has been verified.
Comment 10 Chris Ward 2009-07-03 14:24:18 EDT
~~ Attention - RHEL 5.4 Beta Released! ~~

RHEL 5.4 Beta has been released! There should be a fix present in the Beta release that addresses this particular request. Please test and report back results here, at your earliest convenience. RHEL 5.4 General Availability release is just around the corner!

If you encounter any issues while testing Beta, please describe the issues you have encountered and set the bug into NEED_INFO. If you encounter new issues, please clone this bug to open a new issue and request it be reviewed for inclusion in RHEL 5.4 or a later update, if it is not of urgent severity.

Please do not flip the bug status to VERIFIED. Only post your verification results, and if available, update Verified field with the appropriate value.

Questions can be posted to this bug or your customer or partner representative.
Comment 11 Chris Ward 2009-07-10 15:10:57 EDT
~~ Attention Partners - RHEL 5.4 Snapshot 1 Released! ~~

RHEL 5.4 Snapshot 1 has been released on partners.redhat.com. If you have already reported your test results, you can safely ignore this request. Otherwise, please notice that there should be a fix available now that addresses this particular request. Please test and report back your results here, at your earliest convenience. The RHEL 5.4 exception freeze is quickly approaching.

If you encounter any issues while testing Beta, please describe the issues you have encountered and set the bug into NEED_INFO. If you encounter new issues, please clone this bug to open a new issue and request it be reviewed for inclusion in RHEL 5.4 or a later update, if it is not of urgent severity.

Do not flip the bug status to VERIFIED. Instead, please set your Partner ID in the Verified field above if you have successfully verified the resolution of this issue. 

Further questions can be directed to your Red Hat Partner Manager or other appropriate customer representative.
Comment 14 errata-xmlrpc 2009-09-02 04:49:13 EDT
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on therefore solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.

http://rhn.redhat.com/errata/RHSA-2009-1243.html

Note You need to log in before you can comment on or make changes to this bug.