]> git.baikalelectronics.ru Git - kernel.git/commitdiff
libbpf: Fix alen calculation in libbpf_nla_dump_errormsg()
authorIlya Leoshkevich <iii@linux.ibm.com>
Fri, 10 Feb 2023 00:12:01 +0000 (01:12 +0100)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Sat, 11 Mar 2023 15:43:41 +0000 (16:43 +0100)
[ Upstream commit 17bcd27a08a21397698edf143084d7c87ce17946 ]

The code assumes that everything that comes after nlmsgerr are nlattrs.
When calculating their size, it does not account for the initial
nlmsghdr. This may lead to accessing uninitialized memory.

Fixes: fbf486bfa421 ("libbpf: add error reporting in XDP")
Signed-off-by: Ilya Leoshkevich <iii@linux.ibm.com>
Signed-off-by: Andrii Nakryiko <andrii@kernel.org>
Link: https://lore.kernel.org/bpf/20230210001210.395194-8-iii@linux.ibm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
tools/lib/bpf/nlattr.c

index 1e69c0c8d413f7fb54830783c19c4dac4875fa8f..e610becd03e850fd3fc6db8bee707bfbeaf04aa1 100644 (file)
@@ -177,7 +177,7 @@ int libbpf_nla_dump_errormsg(struct nlmsghdr *nlh)
                hlen += nlmsg_len(&err->msg);
 
        attr = (struct nlattr *) ((void *) err + hlen);
-       alen = nlh->nlmsg_len - hlen;
+       alen = (void *)nlh + nlh->nlmsg_len - (void *)attr;
 
        if (libbpf_nla_parse(tb, NLMSGERR_ATTR_MAX, attr, alen,
                             extack_policy) != 0) {