]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
l2tp: fix incorrect parameter validation in the pppol2tp_getsockopt() function
authorGavrilov Ilia <Ilia.Gavrilov@infotecs.ru>
Thu, 7 Mar 2024 14:23:50 +0000 (14:23 +0000)
committerSasha Levin <sashal@kernel.org>
Tue, 26 Mar 2024 22:21:53 +0000 (18:21 -0400)
[ Upstream commit 955e9876ba4ee26eeaab1b13517f5b2c88e73d55 ]

The 'len' variable can't be negative when assigned the result of
'min_t' because all 'min_t' parameters are cast to unsigned int,
and then the minimum one is chosen.

To fix the logic, check 'len' as read from 'optlen',
where the types of relevant variables are (signed) int.

Fixes: 3557baabf280 ("[L2TP]: PPP over L2TP driver core")
Reviewed-by: Tom Parkin <tparkin@katalix.com>
Signed-off-by: Gavrilov Ilia <Ilia.Gavrilov@infotecs.ru>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
net/l2tp/l2tp_ppp.c

index 5ecc0f20094448ca9a403af7fbc2d00657932ded..b1d89c850f686d484d0da1c83ee4f5a88568babc 100644 (file)
@@ -1357,11 +1357,11 @@ static int pppol2tp_getsockopt(struct socket *sock, int level, int optname,
        if (get_user(len, optlen))
                return -EFAULT;
 
-       len = min_t(unsigned int, len, sizeof(int));
-
        if (len < 0)
                return -EINVAL;
 
+       len = min_t(unsigned int, len, sizeof(int));
+
        err = -ENOTCONN;
        if (!sk->sk_user_data)
                goto end;