| From foo@baz Mon Jan 29 13:22:08 CET 2018 |
| From: Daniel Borkmann <daniel@iogearbox.net> |
| Date: Mon, 29 Jan 2018 02:48:59 +0100 |
| Subject: bpf: fix divides by zero |
| To: gregkh@linuxfoundation.org |
| Cc: ast@kernel.org, stable@vger.kernel.org, Eric Dumazet <edumazet@google.com> |
| Message-ID: <aacafad0b7353aa4acc993dc74ea5168b31d85ab.1517190207.git.daniel@iogearbox.net> |
| |
| From: Eric Dumazet <edumazet@google.com> |
| |
| [ upstream commit c366287ebd698ef5e3de300d90cd62ee9ee7373e ] |
| |
| Divides by zero are not nice, lets avoid them if possible. |
| |
| Also do_div() seems not needed when dealing with 32bit operands, |
| but this seems a minor detail. |
| |
| Fixes: bd4cf0ed331a ("net: filter: rework/optimize internal BPF interpreter's instruction set") |
| Signed-off-by: Eric Dumazet <edumazet@google.com> |
| Reported-by: syzbot <syzkaller@googlegroups.com> |
| Signed-off-by: Alexei Starovoitov <ast@kernel.org> |
| Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
| --- |
| kernel/bpf/core.c | 4 ++-- |
| 1 file changed, 2 insertions(+), 2 deletions(-) |
| |
| --- a/kernel/bpf/core.c |
| +++ b/kernel/bpf/core.c |
| @@ -642,7 +642,7 @@ select_insn: |
| DST = tmp; |
| CONT; |
| ALU_MOD_X: |
| - if (unlikely(SRC == 0)) |
| + if (unlikely((u32)SRC == 0)) |
| return 0; |
| tmp = (u32) DST; |
| DST = do_div(tmp, (u32) SRC); |
| @@ -661,7 +661,7 @@ select_insn: |
| DST = div64_u64(DST, SRC); |
| CONT; |
| ALU_DIV_X: |
| - if (unlikely(SRC == 0)) |
| + if (unlikely((u32)SRC == 0)) |
| return 0; |
| tmp = (u32) DST; |
| do_div(tmp, (u32) SRC); |