Skip to content

Commit 3b3fd06

Browse files
codetronautkuba-moo
authored andcommitted
rose: Fix Null pointer dereference in rose_send_frame()
rose_send_frame() dereferences `neigh->dev` when called from rose_transmit_clear_request(), and the first occurrence of the `neigh` is in rose_loopback_timer() as `rose_loopback_neigh`, and it is initialized in rose_add_loopback_neigh() as NULL. i.e when `rose_loopback_neigh` used in rose_loopback_timer() its `->dev` was still NULL and rose_loopback_timer() was calling rose_rx_call_request() without checking for NULL. - net/rose/rose_link.c This bug seems to get triggered in this line: rose_call = (ax25_address *)neigh->dev->dev_addr; Fix it by adding NULL checking for `rose_loopback_neigh->dev` in rose_loopback_timer(). Fixes: 1da177e ("Linux-2.6.12-rc2") Suggested-by: Jakub Kicinski <[email protected]> Reported-by: [email protected] Tested-by: [email protected] Link: https://syzkaller.appspot.com/bug?id=9d2a7ca8c7f2e4b682c97578dfa3f236258300b3 Signed-off-by: Anmol Karn <[email protected]> Link: https://lore.kernel.org/r/[email protected] Signed-off-by: Jakub Kicinski <[email protected]>
1 parent f46e79a commit 3b3fd06

File tree

1 file changed

+13
-4
lines changed

1 file changed

+13
-4
lines changed

net/rose/rose_loopback.c

Lines changed: 13 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -96,10 +96,19 @@ static void rose_loopback_timer(struct timer_list *unused)
9696
}
9797

9898
if (frametype == ROSE_CALL_REQUEST) {
99-
if ((dev = rose_dev_get(dest)) != NULL) {
100-
if (rose_rx_call_request(skb, dev, rose_loopback_neigh, lci_o) == 0)
101-
kfree_skb(skb);
102-
} else {
99+
if (!rose_loopback_neigh->dev) {
100+
kfree_skb(skb);
101+
continue;
102+
}
103+
104+
dev = rose_dev_get(dest);
105+
if (!dev) {
106+
kfree_skb(skb);
107+
continue;
108+
}
109+
110+
if (rose_rx_call_request(skb, dev, rose_loopback_neigh, lci_o) == 0) {
111+
dev_put(dev);
103112
kfree_skb(skb);
104113
}
105114
} else {

0 commit comments

Comments
 (0)