Commit d4c08afa ("s390/qeth: streamline SNMP cmd code") removed
the bounds checking for req_len, under the assumption that the check in
qeth_alloc_cmd() would suffice.
But that code path isn't sufficiently robust to handle a user-provided
data_length, which could overflow (when adding the cmd header overhead)
before being checked against QETH_BUFSIZE. We end up allocating just a
tiny iob, and the subsequent copy_from_user() writes past the end of
Special-case this path and add a coarse bounds check, to protect against
maliciuous requests. This let's the subsequent code flow do its normal
job and precise checking, without risk of overflow.
Fixes: d4c08afa ("s390/qeth: streamline SNMP cmd code")
Reported-by: Dan Carpenter <firstname.lastname@example.org>
Signed-off-by: Julian Wiedmann <email@example.com>
Reviewed-by: Ursula Braun <firstname.lastname@example.org>
Signed-off-by: David S. Miller <email@example.com>