]> git.ipfire.org Git - people/arne_f/kernel.git/commitdiff
cfg80211: check vendor command doit pointer before use
authorJulian Squires <julian@cipht.net>
Mon, 6 Jul 2020 21:13:53 +0000 (17:13 -0400)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Fri, 21 Aug 2020 07:47:59 +0000 (09:47 +0200)
[ Upstream commit 4052d3d2e8f47a15053320bbcbe365d15610437d ]

In the case where a vendor command does not implement doit, and has no
flags set, doit would not be validated and a NULL pointer dereference
would occur, for example when invoking the vendor command via iw.

I encountered this while developing new vendor commands.  Perhaps in
practice it is advisable to always implement doit along with dumpit,
but it seems reasonable to me to always check doit anyway, not just
when NEED_WDEV.

Signed-off-by: Julian Squires <julian@cipht.net>
Link: https://lore.kernel.org/r/20200706211353.2366470-1-julian@cipht.net
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
net/wireless/nl80211.c

index d0b75781e6f7ab369f5a967df43c31887f310b58..9be7ee322093b4afa2bb004c881968850eb043a6 100644 (file)
@@ -11859,13 +11859,13 @@ static int nl80211_vendor_cmd(struct sk_buff *skb, struct genl_info *info)
                                if (!wdev_running(wdev))
                                        return -ENETDOWN;
                        }
-
-                       if (!vcmd->doit)
-                               return -EOPNOTSUPP;
                } else {
                        wdev = NULL;
                }
 
+               if (!vcmd->doit)
+                       return -EOPNOTSUPP;
+
                if (info->attrs[NL80211_ATTR_VENDOR_DATA]) {
                        data = nla_data(info->attrs[NL80211_ATTR_VENDOR_DATA]);
                        len = nla_len(info->attrs[NL80211_ATTR_VENDOR_DATA]);