There is two variables named 'len' in rtnl_talk. In fact, commit
c079e121a73a didn't work. For example, it was possible to trigger
a seg fault with this command:
$ ip link set gre2 type ip6gre hoplimit 32
Let's rename the argument len to maxlen.
Fixes: c079e121a73a ("libnetlink: add size argument to rtnl_talk")
Reported-by: Thomas Faivre <thomas.faivre@6wind.com>
Signed-off-by: Nicolas Dichtel <nicolas.dichtel@6wind.com>
}
int rtnl_talk(struct rtnl_handle *rtnl, struct nlmsghdr *n,
- struct nlmsghdr *answer, size_t len)
+ struct nlmsghdr *answer, size_t maxlen)
{
int status;
unsigned seq;
} else if (!err->error) {
if (answer)
memcpy(answer, h,
- MIN(len, h->nlmsg_len));
+ MIN(maxlen, h->nlmsg_len));
return 0;
}
if (answer) {
memcpy(answer, h,
- MIN(len, h->nlmsg_len));
+ MIN(maxlen, h->nlmsg_len));
return 0;
}