Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
nl80211: check for the required netlink attributes presence
commit e785fa0a164aa11001cba931367c7f94ffaff888 upstream. nl80211_set_rekey_data() does not check if the required attributes NL80211_REKEY_DATA_{REPLAY_CTR,KEK,KCK} are present when processing NL80211_CMD_SET_REKEY_OFFLOAD request. This request can be issued by users with CAP_NET_ADMIN privilege and may result in NULL dereference and a system crash. Add a check for the required attributes presence. This patch is based on the patch by bo Zhang. This fixes CVE-2017-12153. Change-Id: Ifb64d8c664a83433b8e623ecc45c64e3a0139153 References: https://bugzilla.redhat.com/show_bug.cgi?id=1491046 Fixes: e5497d7 ("cfg80211/nl80211: support GTK rekey offload") Reported-by: bo Zhang <[email protected]> Signed-off-by: Vladis Dronov <[email protected]> Signed-off-by: Johannes Berg <[email protected]> Signed-off-by: Ben Hutchings <[email protected]> Signed-off-by: Francisco Franco <[email protected]>
- Loading branch information