From 36c05d26811f331cac0d1653ef5752e000588d64 Mon Sep 17 00:00:00 2001 From: Andrew Hyatt Date: Wed, 18 Mar 2020 16:17:00 -0400 Subject: [PATCH] Fix stack corruption in getsockopt The option was inspected without considering the protocol level. This could lead to a false assumption of the size of the passed in buffer. Fixes #303 --- src/kernel/emulation/linux/network/getsockopt.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/src/kernel/emulation/linux/network/getsockopt.c b/src/kernel/emulation/linux/network/getsockopt.c index 7c69e69df..1b8727245 100644 --- a/src/kernel/emulation/linux/network/getsockopt.c +++ b/src/kernel/emulation/linux/network/getsockopt.c @@ -57,7 +57,8 @@ long sys_getsockopt(int fd, int level, int optname, void* optval, int* optlen) int sockopt_bsd_to_linux(int* level, int* optname, void** optval, void* optbuf) { - if (*optname == LOCAL_PEERCRED) + /* TCP_NODELAY and LOCAL_PEERCRED both have values of 1 */ + if (*optname == LOCAL_PEERCRED && *level == IPPROTO_IP) { struct xucred* c = (struct xucred*) optbuf; // Simulate euid 0 -- 2.51.2