Description
In the Linux kernel, the following vulnerability has been resolved: net_sched: keep alloc_hash updated after hash allocation In commit 599be01ee567 ("net_sched: fix an OOB access in cls_tcindex") I moved cp->hash calculation before the first tcindex_alloc_perfect_hash(), but cp->alloc_hash is left untouched. This difference could lead to another out of bound access. cp->alloc_hash should always be the size allocated, we should update it after this tcindex_alloc_perfect_hash().
Product status
73c29d2f6f8ae731b1e09051b69ed3ba2319482b (git) before d6cdc5bb19b595486fb2e6661e5138d73a57f454
b974ac51f5834a729de252fc5c1c9de9efd79b45 (git) before c4453d2833671e3a9f6bd52f0f581056c3736386
6cb448ee493c8a514c9afa0c346f3f5b3227de85 (git) before 9f8b6c44be178c2498a00b270872a6e30e7c8266
478c4b2ffd44e5186c7e22ae7c38a86a5b9cfde5 (git) before 557d015ffb27b672e24e6ad141fd887783871dc2
dd8142a6fa5270783d415292ec8169f4ea2a5468 (git) before d23faf32e577922b6da20bf3740625c1105381bf
2c66ff8d08f81bcf8e8cb22e31e39c051b15336a (git) before bd3ee8fb6371b45c71c9345cc359b94da2ddefa9
599be01ee567b61f4471ee8078870847d0a11e8e (git) before 0d1c3530e1bd38382edef72591b78e877e0edcd3
4.4.214 (semver) before 4.4.218
4.9.214 (semver) before 4.9.218
4.14.171 (semver) before 4.14.175
4.19.103 (semver) before 4.19.114
5.4.19 (semver) before 5.4.29
5.5.3 (semver) before 5.5.14
References
git.kernel.org/...c/d6cdc5bb19b595486fb2e6661e5138d73a57f454
git.kernel.org/...c/c4453d2833671e3a9f6bd52f0f581056c3736386
git.kernel.org/...c/9f8b6c44be178c2498a00b270872a6e30e7c8266
git.kernel.org/...c/557d015ffb27b672e24e6ad141fd887783871dc2
git.kernel.org/...c/d23faf32e577922b6da20bf3740625c1105381bf
git.kernel.org/...c/bd3ee8fb6371b45c71c9345cc359b94da2ddefa9
git.kernel.org/...c/0d1c3530e1bd38382edef72591b78e877e0edcd3
syzkaller.appspot.com/...693da894e7b078d18fca2c9c0a19b457534
blog.cdthoughts.ch/2021/03/16/syzbot-bug.html