diff options
author | Martin Murray <murrayma@citi.umich.edu> | 2006-01-10 16:02:29 -0500 |
---|---|---|
committer | David S. Miller <davem@davemloft.net> | 2006-01-10 16:02:29 -0500 |
commit | ad8e4b75c8a7bed475d72ce09bf5267188621961 (patch) | |
tree | fe9edd967818a744f87c2d1aa51443bae613fbbf /net/netlink | |
parent | babbdb1a18d37e57acae7e348ef122f2b905df0a (diff) |
[AF_NETLINK]: Fix DoS in netlink_rcv_skb()
From: Martin Murray <murrayma@citi.umich.edu>
Sanity check nlmsg_len during netlink_rcv_skb. An nlmsg_len == 0 can
cause infinite loop in kernel, effectively DoSing machine. Noted by
Matin Murray.
Signed-off-by: Chris Wright <chrisw@sous-sol.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
Diffstat (limited to 'net/netlink')
-rw-r--r-- | net/netlink/af_netlink.c | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/net/netlink/af_netlink.c b/net/netlink/af_netlink.c index a67f1b44c9a3..bb50c8a9fcad 100644 --- a/net/netlink/af_netlink.c +++ b/net/netlink/af_netlink.c | |||
@@ -1422,7 +1422,7 @@ static int netlink_rcv_skb(struct sk_buff *skb, int (*cb)(struct sk_buff *, | |||
1422 | while (skb->len >= nlmsg_total_size(0)) { | 1422 | while (skb->len >= nlmsg_total_size(0)) { |
1423 | nlh = (struct nlmsghdr *) skb->data; | 1423 | nlh = (struct nlmsghdr *) skb->data; |
1424 | 1424 | ||
1425 | if (skb->len < nlh->nlmsg_len) | 1425 | if (nlh->nlmsg_len < NLMSG_HDRLEN || skb->len < nlh->nlmsg_len) |
1426 | return 0; | 1426 | return 0; |
1427 | 1427 | ||
1428 | total_len = min(NLMSG_ALIGN(nlh->nlmsg_len), skb->len); | 1428 | total_len = min(NLMSG_ALIGN(nlh->nlmsg_len), skb->len); |