net: ieee802154: fix nl802154 del llsec devkey
authorAlexander Aring <aahringo@redhat.com>
Sun, 21 Feb 2021 17:43:21 +0000 (12:43 -0500)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Fri, 16 Apr 2021 09:59:10 +0000 (11:59 +0200)
commit 27c746869e1a135dffc2f2a80715bb7aa00445b4 upstream.

This patch fixes a nullpointer dereference if NL802154_ATTR_SEC_DEVKEY is
not set by the user. If this is the case nl802154 will return -EINVAL.

Reported-by: syzbot+368672e0da240db53b5f@syzkaller.appspotmail.com
Signed-off-by: Alexander Aring <aahringo@redhat.com>
Link: https://lore.kernel.org/r/20210221174321.14210-4-aahringo@redhat.com
Signed-off-by: Stefan Schmidt <stefan@datenfreihafen.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
net/ieee802154/nl802154.c

index 489eb256ee2a3c1f4c71b035d6a9d033d0e363b3..4ce2b89df4c8093138c6eda438c8baf2e2daa3b0 100644 (file)
@@ -1958,7 +1958,8 @@ static int nl802154_del_llsec_devkey(struct sk_buff *skb, struct genl_info *info
        struct ieee802154_llsec_device_key key;
        __le64 extended_addr;
 
-       if (nla_parse_nested(attrs, NL802154_DEVKEY_ATTR_MAX,
+       if (!info->attrs[NL802154_ATTR_SEC_DEVKEY] ||
+           nla_parse_nested(attrs, NL802154_DEVKEY_ATTR_MAX,
                             info->attrs[NL802154_ATTR_SEC_DEVKEY],
                             nl802154_devkey_policy))
                return -EINVAL;