Received: by 2002:a05:6a10:9848:0:0:0:0 with SMTP id x8csp2854697pxf; Sun, 4 Apr 2021 17:38:33 -0700 (PDT) X-Google-Smtp-Source: ABdhPJyJLfDT/jWB8+IYuk8+JBhatzaBqOMpz3a5YQj7t2TcAXHQfqJVaRgo0SIv8K4tRa9KKrbd X-Received: by 2002:a92:ad11:: with SMTP id w17mr16394734ilh.199.1617583113759; Sun, 04 Apr 2021 17:38:33 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1617583113; cv=none; d=google.com; s=arc-20160816; b=EkCs1Vatj16/Kw8ws28IMleff68/H18nVJN2ywh4aDb5uxEKQjTo+1ZOl5EP269ajT 6t/m6TAl++a6evJVJUax0DawatZrVYFGrvUckMdYJPdi/f2BT9H7vhzMAGdjw7hwaSei 0yeRnqUt9M63tMdT8ANFElB+Wvqr3o4b3wZsORDRL7+k806vLYpraN8DkIWRc5OisxuV C3oEMt9tbaAulYp3etiXv1fI8DV4PQZ3rtebXqg9CbyP2vsQWBiTBEws5VvR+kpEY06u ccDVGU+OoRFUPF6k8mljtFdyd+zbqhYRcrbKI0qIwaTv4oyIB2y7sJfI/b4xk5BjYQln 4MDA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:dkim-signature; bh=1lsInjJ8vrGaLsH6CKaq8WMLDPwzsuEN+yGUjpTexzo=; b=KzX1JBYEyS+fVkMIBOCJn2tbQ8ZAgJZ6RXWB0+5OKAjDDzp/iwrEtYekwlkIyIkibE G+F+KZLz6qV0J3SVCgbwtRcSGalIPWNS3xfCdqXuU3FWnKkGN+7psNmKr3hh1flUMRBn 9PMAJXl4Zph+UIo3h+IYOg0eC1Xvd9/MQ2X0FlSn0QJY5l8g7dKzOAKnE25vAmmk3mfQ 6cfkP6AOkw6siDOFZ0+gsNaYxW6BappvSYtMi1KJgEBFf62A+sFB2tzUzThK9o/ckgqN jw38qrnvmyL8s8IR/AyKzyUhndulBSCbWY/gsqwYfTrjy2PikiSkHZlum+p62VJAfZET 0d5w== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@gmail.com header.s=20161025 header.b=XPvoXBl6; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id t9si13508463ilu.69.2021.04.04.17.38.18; Sun, 04 Apr 2021 17:38:33 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=pass header.i=@gmail.com header.s=20161025 header.b=XPvoXBl6; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S231694AbhDEAh0 (ORCPT + 99 others); Sun, 4 Apr 2021 20:37:26 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:58712 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S230052AbhDEAhY (ORCPT ); Sun, 4 Apr 2021 20:37:24 -0400 Received: from mail-oi1-x232.google.com (mail-oi1-x232.google.com [IPv6:2607:f8b0:4864:20::232]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 3CD0AC061756; Sun, 4 Apr 2021 17:37:12 -0700 (PDT) Received: by mail-oi1-x232.google.com with SMTP id z15so10267945oic.8; Sun, 04 Apr 2021 17:37:12 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=1lsInjJ8vrGaLsH6CKaq8WMLDPwzsuEN+yGUjpTexzo=; b=XPvoXBl6C34rtFpUT8m+gzTvzaeQyZk3D8EEKgHXPyIrb8bRHSZHH8XUPEdwy1FzJg VDmJVhDELixgsqx4GNwmOi0CzN5OL38Oe17z3gATB4o48T8MowhdxxtgY2qIEGP3VWpn EPnSrXtN2KqvoBKzHEOzHABkok+30D60Xe48orKZGcKAhDFouZA4042h5vCLG57NiA6s Gy0pmtxVDP41/iu5imr5xd3kcGAB3RyQ1D+M37PQ4Zq42yI6bj8EdeWyJl8n/I9usGyR 4pfAbUKQg4HwJa2MTVKWcWsARuv/BYycqZAexckZ9niMLbXuw5jPhQfwxNg3MC+QzqOc +FeA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=1lsInjJ8vrGaLsH6CKaq8WMLDPwzsuEN+yGUjpTexzo=; b=FPwvT9vz8Tbr6+fyGZXF9U5oVQradf1UsAubqazbL/hLpgtBpIvCL+LrbJq3wLUnhH WBycvgfV1B18rLJwqc+hsJvoy5105ljK8bSX+HS5owfGunZRXVFh6KRFheqLOT3DBKJQ LuSp1+QS9qD8cOdffsLznMoIrX2ERhOAWoIBfFdOPP4M0ETHe1ZM7MVrOjeEKzZAz7j9 wzeimedfyivFnnCWZtjYZnGpObAimi7xc26F3Ynb0p6INzfRKrTM0+cgXWcfwkJaLB9R TS6O0aoFsxgI4s5fW8HFChN83gagUmlzN2P8vtlRvo3qr8xecGrs4BPP1/pC44BK8yyQ Q0nw== X-Gm-Message-State: AOAM531rvw6ZUSVBA/+HjNwKhSl7VWVVjrZM1otsA7o0cc6acv0E+2xf zSex6mMnyJNuJ3sEHBOFI7or7FFTA+gKQSeh3oM= X-Received: by 2002:a05:6808:f14:: with SMTP id m20mr16953443oiw.13.1617583031630; Sun, 04 Apr 2021 17:37:11 -0700 (PDT) MIME-Version: 1.0 References: <20210403151851.9437-1-paskripkin@gmail.com> In-Reply-To: <20210403151851.9437-1-paskripkin@gmail.com> From: Alexander Aring Date: Sun, 4 Apr 2021 20:37:00 -0400 Message-ID: Subject: Re: [PATCH] net: fix NULL ptr dereference in nl802154_del_llsec_key To: Pavel Skripkin Cc: Stefan Schmidt , "David S. Miller" , linux-wpan - ML , "open list:NETWORKING [GENERAL]" , kernel list , syzbot+ac5c11d2959a8b3c4806@syzkaller.appspotmail.com Content-Type: text/plain; charset="UTF-8" Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Hi, On Sat, 3 Apr 2021 at 11:18, Pavel Skripkin wrote: > > syzbot reported NULL ptr dereference in nl802154_del_llsec_key()[1] > The problem was in case of info->attrs[NL802154_ATTR_SEC_KEY] == NULL. > nla_parse_nested_deprecated()[2] doesn't check this condition before calling > nla_len()[3] > this is already fixed in the same way just not in net yet. - Alex