From 78eebdbc7d2f96b01a18d7db33c1c99266efc4bc Mon Sep 17 00:00:00 2001 From: Max Kunzelmann Date: Tue, 7 Nov 2023 01:20:55 +0000 Subject: [PATCH] libnetlink: validate nlmsg header length first Validate the nlmsg header length before accessing the nlmsg payload length. Fixes: 892a25e286fb ("libnetlink: break up dump function") Signed-off-by: Max Kunzelmann Reviewed-by: Benny Baumann Reviewed-by: Robert Geislinger Signed-off-by: Stephen Hemminger --- lib/libnetlink.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/lib/libnetlink.c b/lib/libnetlink.c index 7edcd2856..016482294 100644 --- a/lib/libnetlink.c +++ b/lib/libnetlink.c @@ -727,13 +727,15 @@ int rtnl_dump_request_n(struct rtnl_handle *rth, struct nlmsghdr *n) static int rtnl_dump_done(struct nlmsghdr *h, const struct rtnl_dump_filter_arg *a) { - int len = *(int *)NLMSG_DATA(h); + int len; if (h->nlmsg_len < NLMSG_LENGTH(sizeof(int))) { fprintf(stderr, "DONE truncated\n"); return -1; } + len = *(int *)NLMSG_DATA(h); + if (len < 0) { errno = -len;