diff options
| author | Norbert Slusarek <nslusarek@gmx.net> | 2021-06-20 14:38:42 +0200 |
|---|---|---|
| committer | Greg Kroah-Hartman <gregkh@linuxfoundation.org> | 2021-07-14 17:00:01 +0200 |
| commit | eedb3cfb4c6f6852a1bccfa79347e057e275bd1c (patch) | |
| tree | 39a59d8643d65156c737ce17ee85d3de0293e1a1 /net | |
| parent | bd5046d72d9096c98a3d1f71e5abef7832a4d8cf (diff) | |
| download | linux-eedb3cfb4c6f6852a1bccfa79347e057e275bd1c.tar.gz linux-eedb3cfb4c6f6852a1bccfa79347e057e275bd1c.tar.bz2 linux-eedb3cfb4c6f6852a1bccfa79347e057e275bd1c.zip | |
can: j1939: j1939_sk_setsockopt(): prevent allocation of j1939 filter for optlen == 0
[ Upstream commit aaf473d0100f64abc88560e2bea905805bcf2a8e ]
If optval != NULL and optlen == 0 are specified for SO_J1939_FILTER in
j1939_sk_setsockopt(), memdup_sockptr() will return ZERO_PTR for 0
size allocation. The new filter will be mistakenly assigned ZERO_PTR.
This patch checks for optlen != 0 and filter will be assigned NULL in
case of optlen == 0.
Fixes: 9d71dd0c7009 ("can: add support of SAE J1939 protocol")
Link: https://lore.kernel.org/r/20210620123842.117975-1-nslusarek@gmx.net
Signed-off-by: Norbert Slusarek <nslusarek@gmx.net>
Acked-by: Oleksij Rempel <o.rempel@pengutronix.de>
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Diffstat (limited to 'net')
| -rw-r--r-- | net/can/j1939/socket.c | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/net/can/j1939/socket.c b/net/can/j1939/socket.c index fce8bc8afeb7..e1a399821238 100644 --- a/net/can/j1939/socket.c +++ b/net/can/j1939/socket.c @@ -676,7 +676,7 @@ static int j1939_sk_setsockopt(struct socket *sock, int level, int optname, switch (optname) { case SO_J1939_FILTER: - if (!sockptr_is_null(optval)) { + if (!sockptr_is_null(optval) && optlen != 0) { struct j1939_filter *f; int c; |
