diff options
author | Tetsuo Handa <penguin-kernel@I-love.SAKURA.ne.jp> | 2022-10-01 18:43:44 +0200 |
---|---|---|
committer | David S. Miller <davem@davemloft.net> | 2022-10-03 14:26:41 +0200 |
commit | 3a4d061c699bd3eedc80dc97a4b2a2e1af83c6f5 (patch) | |
tree | e2a5c714c310bc75d97db404ad69e522eca9a2ef /net/ieee802154/socket.c | |
parent | net: wwan: iosm: Call mutex_init before locking it (diff) | |
download | linux-3a4d061c699bd3eedc80dc97a4b2a2e1af83c6f5.tar.xz linux-3a4d061c699bd3eedc80dc97a4b2a2e1af83c6f5.zip |
net/ieee802154: reject zero-sized raw_sendmsg()
syzbot is hitting skb_assert_len() warning at raw_sendmsg() for ieee802154
socket. What commit dc633700f00f726e ("net/af_packet: check len when
min_header_len equals to 0") does also applies to ieee802154 socket.
Link: https://syzkaller.appspot.com/bug?extid=5ea725c25d06fb9114c4
Reported-by: syzbot <syzbot+5ea725c25d06fb9114c4@syzkaller.appspotmail.com>
Fixes: fd1894224407c484 ("bpf: Don't redirect packets with invalid pkt_len")
Signed-off-by: Tetsuo Handa <penguin-kernel@I-love.SAKURA.ne.jp>
Signed-off-by: David S. Miller <davem@davemloft.net>
Diffstat (limited to '')
-rw-r--r-- | net/ieee802154/socket.c | 3 |
1 files changed, 3 insertions, 0 deletions
diff --git a/net/ieee802154/socket.c b/net/ieee802154/socket.c index 7889e1ef7fad..cbd0e2ac4ffe 100644 --- a/net/ieee802154/socket.c +++ b/net/ieee802154/socket.c @@ -251,6 +251,9 @@ static int raw_sendmsg(struct sock *sk, struct msghdr *msg, size_t size) return -EOPNOTSUPP; } + if (!size) + return -EINVAL; + lock_sock(sk); if (!sk->sk_bound_dev_if) dev = dev_getfirstbyhwtype(sock_net(sk), ARPHRD_IEEE802154); |