| From 1e2af0d0f29d6b6256ef03cf788184684ee9cb07 Mon Sep 17 00:00:00 2001 |
| From: Nicolas Dichtel <nicolas.dichtel@6wind.com> |
| Date: Fri, 14 Jun 2019 11:13:55 +0200 |
| Subject: xfrm: fix sa selector validation |
| |
| [ Upstream commit b8d6d0079757cbd1b69724cfd1c08e2171c68cee ] |
| |
| After commit b38ff4075a80, the following command does not work anymore: |
| $ ip xfrm state add src 10.125.0.2 dst 10.125.0.1 proto esp spi 34 reqid 1 \ |
| mode tunnel enc 'cbc(aes)' 0xb0abdba8b782ad9d364ec81e3a7d82a1 auth-trunc \ |
| 'hmac(sha1)' 0xe26609ebd00acb6a4d51fca13e49ea78a72c73e6 96 flag align4 |
| |
| In fact, the selector is not mandatory, allow the user to provide an empty |
| selector. |
| |
| Fixes: b38ff4075a80 ("xfrm: Fix xfrm sel prefix length validation") |
| CC: Anirudh Gupta <anirudh.gupta@sophos.com> |
| Signed-off-by: Nicolas Dichtel <nicolas.dichtel@6wind.com> |
| Acked-by: Herbert Xu <herbert@gondor.apana.org.au> |
| Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com> |
| Signed-off-by: Sasha Levin <sashal@kernel.org> |
| --- |
| net/xfrm/xfrm_user.c | 3 +++ |
| 1 file changed, 3 insertions(+) |
| |
| diff --git a/net/xfrm/xfrm_user.c b/net/xfrm/xfrm_user.c |
| index b25b68ae7c74..150c58dc8a7b 100644 |
| --- a/net/xfrm/xfrm_user.c |
| +++ b/net/xfrm/xfrm_user.c |
| @@ -166,6 +166,9 @@ static int verify_newsa_info(struct xfrm_usersa_info *p, |
| } |
| |
| switch (p->sel.family) { |
| + case AF_UNSPEC: |
| + break; |
| + |
| case AF_INET: |
| if (p->sel.prefixlen_d > 32 || p->sel.prefixlen_s > 32) |
| goto out; |
| -- |
| 2.20.1 |
| |