[Linux-kernel-mentees] [PATCH] net: wireless: nl80211: fix out-of-bounds access in nl80211_del_key()

patchwork-bot+netdevbpf at kernel.org patchwork-bot+netdevbpf at kernel.org
Thu Oct 8 20:00:05 UTC 2020


Hello:

This patch was applied to netdev/net.git (refs/heads/master):

On Wed,  7 Oct 2020 09:24:01 +0530 you wrote:
> In nl80211_parse_key(), key.idx is first initialized as -1.
> If this value of key.idx remains unmodified and gets returned, and
> nl80211_key_allowed() also returns 0, then rdev_del_key() gets called
> with key.idx = -1.
> This causes an out-of-bounds array access.
> 
> Handle this issue by checking if the value of key.idx after
> nl80211_parse_key() is called and return -EINVAL if key.idx < 0.
> 
> [...]

Here is the summary with links:
  - net: wireless: nl80211: fix out-of-bounds access in nl80211_del_key()
    https://git.kernel.org/netdev/net/c/3dc289f8f139

You are awesome, thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html




More information about the Linux-kernel-mentees mailing list