summaryrefslogtreecommitdiffstats
path: root/net/ieee802154/socket.c
diff options
context:
space:
mode:
authorTetsuo Handa <penguin-kernel@I-love.SAKURA.ne.jp>2022-10-01 18:43:44 +0200
committerDavid S. Miller <davem@davemloft.net>2022-10-03 14:26:41 +0200
commit3a4d061c699bd3eedc80dc97a4b2a2e1af83c6f5 (patch)
treee2a5c714c310bc75d97db404ad69e522eca9a2ef /net/ieee802154/socket.c
parentnet: wwan: iosm: Call mutex_init before locking it (diff)
downloadlinux-3a4d061c699bd3eedc80dc97a4b2a2e1af83c6f5.tar.xz
linux-3a4d061c699bd3eedc80dc97a4b2a2e1af83c6f5.zip
net/ieee802154: reject zero-sized raw_sendmsg()
syzbot is hitting skb_assert_len() warning at raw_sendmsg() for ieee802154 socket. What commit dc633700f00f726e ("net/af_packet: check len when min_header_len equals to 0") does also applies to ieee802154 socket. Link: https://syzkaller.appspot.com/bug?extid=5ea725c25d06fb9114c4 Reported-by: syzbot <syzbot+5ea725c25d06fb9114c4@syzkaller.appspotmail.com> Fixes: fd1894224407c484 ("bpf: Don't redirect packets with invalid pkt_len") Signed-off-by: Tetsuo Handa <penguin-kernel@I-love.SAKURA.ne.jp> Signed-off-by: David S. Miller <davem@davemloft.net>
Diffstat (limited to '')
-rw-r--r--net/ieee802154/socket.c3
1 files changed, 3 insertions, 0 deletions
diff --git a/net/ieee802154/socket.c b/net/ieee802154/socket.c
index 7889e1ef7fad..cbd0e2ac4ffe 100644
--- a/net/ieee802154/socket.c
+++ b/net/ieee802154/socket.c
@@ -251,6 +251,9 @@ static int raw_sendmsg(struct sock *sk, struct msghdr *msg, size_t size)
return -EOPNOTSUPP;
}
+ if (!size)
+ return -EINVAL;
+
lock_sock(sk);
if (!sk->sk_bound_dev_if)
dev = dev_getfirstbyhwtype(sock_net(sk), ARPHRD_IEEE802154);