summaryrefslogtreecommitdiff
path: root/net/nfc
diff options
context:
space:
mode:
authorYoung Xiao <92siuyang@gmail.com>2019-06-14 15:13:02 +0800
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>2019-06-22 08:15:14 +0200
commit4bb4ba362cc1ed3acb181a6d0b68c6de22be78e2 (patch)
tree0e76554aed89ed82c362e963ca4ad8bfe1e43b16 /net/nfc
parent7530c3f3d5b9035c445885f3f52b16533654e9dc (diff)
nfc: Ensure presence of required attributes in the deactivate_target handler
[ Upstream commit 385097a3675749cbc9e97c085c0e5dfe4269ca51 ] Check that the NFC_ATTR_TARGET_INDEX attributes (in addition to NFC_ATTR_DEVICE_INDEX) are provided by the netlink client prior to accessing them. This prevents potential unhandled NULL pointer dereference exceptions which can be triggered by malicious user-mode programs, if they omit one or both of these attributes. Signed-off-by: Young Xiao <92siuyang@gmail.com> Signed-off-by: David S. Miller <davem@davemloft.net> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Diffstat (limited to 'net/nfc')
-rw-r--r--net/nfc/netlink.c3
1 files changed, 2 insertions, 1 deletions
diff --git a/net/nfc/netlink.c b/net/nfc/netlink.c
index 376181cc1def..9f2875efb4ac 100644
--- a/net/nfc/netlink.c
+++ b/net/nfc/netlink.c
@@ -922,7 +922,8 @@ static int nfc_genl_deactivate_target(struct sk_buff *skb,
u32 device_idx, target_idx;
int rc;
- if (!info->attrs[NFC_ATTR_DEVICE_INDEX])
+ if (!info->attrs[NFC_ATTR_DEVICE_INDEX] ||
+ !info->attrs[NFC_ATTR_TARGET_INDEX])
return -EINVAL;
device_idx = nla_get_u32(info->attrs[NFC_ATTR_DEVICE_INDEX]);