From: Gavrilov Ilia Date: Thu, 7 Mar 2024 14:23:50 +0000 (+0000) Subject: l2tp: fix incorrect parameter validation in the pppol2tp_getsockopt() function X-Git-Tag: v6.9-rc1~159^2~32^2~3 X-Git-Url: http://git.ipfire.org/?a=commitdiff_plain;h=955e9876ba4ee26eeaab1b13517f5b2c88e73d55;p=thirdparty%2Fkernel%2Flinux.git l2tp: fix incorrect parameter validation in the pppol2tp_getsockopt() function The 'len' variable can't be negative when assigned the result of 'min_t' because all 'min_t' parameters are cast to unsigned int, and then the minimum one is chosen. To fix the logic, check 'len' as read from 'optlen', where the types of relevant variables are (signed) int. Fixes: 3557baabf280 ("[L2TP]: PPP over L2TP driver core") Reviewed-by: Tom Parkin Signed-off-by: Gavrilov Ilia Signed-off-by: David S. Miller --- diff --git a/net/l2tp/l2tp_ppp.c b/net/l2tp/l2tp_ppp.c index f011af6601c9c..6146e4e67bbb5 100644 --- a/net/l2tp/l2tp_ppp.c +++ b/net/l2tp/l2tp_ppp.c @@ -1356,11 +1356,11 @@ static int pppol2tp_getsockopt(struct socket *sock, int level, int optname, if (get_user(len, optlen)) return -EFAULT; - len = min_t(unsigned int, len, sizeof(int)); - if (len < 0) return -EINVAL; + len = min_t(unsigned int, len, sizeof(int)); + err = -ENOTCONN; if (!sk->sk_user_data) goto end;