| From 18917d51472fe3b126a3a8f756c6b18085eb8130 Mon Sep 17 00:00:00 2001 |
| From: Andrey Konovalov <andreyknvl@google.com> |
| Date: Mon, 29 Jul 2019 16:35:01 +0300 |
| Subject: NFC: fix attrs checks in netlink interface |
| |
| From: Andrey Konovalov <andreyknvl@google.com> |
| |
| commit 18917d51472fe3b126a3a8f756c6b18085eb8130 upstream. |
| |
| nfc_genl_deactivate_target() relies on the NFC_ATTR_TARGET_INDEX |
| attribute being present, but doesn't check whether it is actually |
| provided by the user. Same goes for nfc_genl_fw_download() and |
| NFC_ATTR_FIRMWARE_NAME. |
| |
| This patch adds appropriate checks. |
| |
| Found with syzkaller. |
| |
| Signed-off-by: Andrey Konovalov <andreyknvl@google.com> |
| Signed-off-by: Andy Shevchenko <andriy.shevchenko@linux.intel.com> |
| Signed-off-by: David S. Miller <davem@davemloft.net> |
| Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
| |
| --- |
| net/nfc/netlink.c | 6 ++++-- |
| 1 file changed, 4 insertions(+), 2 deletions(-) |
| |
| --- a/net/nfc/netlink.c |
| +++ b/net/nfc/netlink.c |
| @@ -973,7 +973,8 @@ static int nfc_genl_dep_link_down(struct |
| int rc; |
| u32 idx; |
| |
| - if (!info->attrs[NFC_ATTR_DEVICE_INDEX]) |
| + if (!info->attrs[NFC_ATTR_DEVICE_INDEX] || |
| + !info->attrs[NFC_ATTR_TARGET_INDEX]) |
| return -EINVAL; |
| |
| idx = nla_get_u32(info->attrs[NFC_ATTR_DEVICE_INDEX]); |
| @@ -1022,7 +1023,8 @@ static int nfc_genl_llc_get_params(struc |
| struct sk_buff *msg = NULL; |
| u32 idx; |
| |
| - if (!info->attrs[NFC_ATTR_DEVICE_INDEX]) |
| + if (!info->attrs[NFC_ATTR_DEVICE_INDEX] || |
| + !info->attrs[NFC_ATTR_FIRMWARE_NAME]) |
| return -EINVAL; |
| |
| idx = nla_get_u32(info->attrs[NFC_ATTR_DEVICE_INDEX]); |