[PATCH iproute2] libnetlink: check error handler is present before a call

Subsystems: library code, the rest

STALE1871d

3 messages, 3 authors, 2021-07-11 · open the first message on its own page

[PATCH iproute2] libnetlink: check error handler is present before a call

From: Alexander Mikhalitsyn <hidden>
Date: 2021-07-11 11:15:55

Fix nullptr dereference of errhndlr from rtnl_dump_filter_arg
struct in rtnl_dump_done and rtnl_dump_error functions.

Fixes: 459ce6e3d792 ("ip route: ignore ENOENT during save if RT_TABLE_MAIN is being dumped")
Cc: Stephen Hemminger <stephen@networkplumber.org>
Cc: Roi Dayan <redacted>
Cc: Alexander Mikhalitsyn <redacted>
Reported-by: Roi Dayan <redacted>
Signed-off-by: Alexander Mikhalitsyn <redacted>
---
 lib/libnetlink.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/lib/libnetlink.c b/lib/libnetlink.c
index e9b8c3bd..d068dbe2 100644
--- a/lib/libnetlink.c
+++ b/lib/libnetlink.c
@@ -686,7 +686,7 @@ static int rtnl_dump_done(struct nlmsghdr *h,
 	if (len < 0) {
 		errno = -len;
 
-		if (a->errhndlr(h, a->arg2) & RTNL_SUPPRESS_NLMSG_DONE_NLERR)
+		if (a->errhndlr && (a->errhndlr(h, a->arg2) & RTNL_SUPPRESS_NLMSG_DONE_NLERR))
 			return 0;
 
 		/* check for any messages returned from kernel */
@@ -729,7 +729,7 @@ static int rtnl_dump_error(const struct rtnl_handle *rth,
 		     errno == EOPNOTSUPP))
 			return -1;
 
-		if (a->errhndlr(h, a->arg2) & RTNL_SUPPRESS_NLMSG_ERROR_NLERR)
+		if (a->errhndlr && (a->errhndlr(h, a->arg2) & RTNL_SUPPRESS_NLMSG_ERROR_NLERR))
 			return 0;
 
 		if (!(rth->flags & RTNL_HANDLE_F_SUPPRESS_NLERR))
-- 
2.31.1

Re: [PATCH iproute2] libnetlink: check error handler is present before a call

From: Roi Dayan <hidden>
Date: 2021-07-11 11:18:37


On 2021-07-11 2:15 PM, Alexander Mikhalitsyn wrote:
quoted hunk
Fix nullptr dereference of errhndlr from rtnl_dump_filter_arg
struct in rtnl_dump_done and rtnl_dump_error functions.

Fixes: 459ce6e3d792 ("ip route: ignore ENOENT during save if RT_TABLE_MAIN is being dumped")
Cc: Stephen Hemminger <stephen@networkplumber.org>
Cc: Roi Dayan <redacted>
Cc: Alexander Mikhalitsyn <redacted>
Reported-by: Roi Dayan <redacted>
Signed-off-by: Alexander Mikhalitsyn <redacted>
---
  lib/libnetlink.c | 4 ++--
  1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/lib/libnetlink.c b/lib/libnetlink.c
index e9b8c3bd..d068dbe2 100644
--- a/lib/libnetlink.c
+++ b/lib/libnetlink.c
@@ -686,7 +686,7 @@ static int rtnl_dump_done(struct nlmsghdr *h,
  	if (len < 0) {
  		errno = -len;
  
-		if (a->errhndlr(h, a->arg2) & RTNL_SUPPRESS_NLMSG_DONE_NLERR)
+		if (a->errhndlr && (a->errhndlr(h, a->arg2) & RTNL_SUPPRESS_NLMSG_DONE_NLERR))
  			return 0;
  
  		/* check for any messages returned from kernel */
@@ -729,7 +729,7 @@ static int rtnl_dump_error(const struct rtnl_handle *rth,
  		     errno == EOPNOTSUPP))
  			return -1;
  
-		if (a->errhndlr(h, a->arg2) & RTNL_SUPPRESS_NLMSG_ERROR_NLERR)
+		if (a->errhndlr && (a->errhndlr(h, a->arg2) & RTNL_SUPPRESS_NLMSG_ERROR_NLERR))
  			return 0;
  
  		if (!(rth->flags & RTNL_HANDLE_F_SUPPRESS_NLERR))
that was quick. was about to send the exact same patch :)
so tested as well. thanks!

Reviewed-by: Roi Dayan <redacted>

Re: [PATCH iproute2] libnetlink: check error handler is present before a call

From: Alexander Mihalicyn <hidden>
Date: 2021-07-11 11:26:31

On Sun, Jul 11, 2021 at 2:18 PM Roi Dayan [off-list ref] wrote:


On 2021-07-11 2:15 PM, Alexander Mikhalitsyn wrote:
quoted
Fix nullptr dereference of errhndlr from rtnl_dump_filter_arg
struct in rtnl_dump_done and rtnl_dump_error functions.

Fixes: 459ce6e3d792 ("ip route: ignore ENOENT during save if RT_TABLE_MAIN is being dumped")
Cc: Stephen Hemminger <stephen@networkplumber.org>
Cc: Roi Dayan <redacted>
Cc: Alexander Mikhalitsyn <redacted>
Reported-by: Roi Dayan <redacted>
Signed-off-by: Alexander Mikhalitsyn <redacted>
---
  lib/libnetlink.c | 4 ++--
  1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/lib/libnetlink.c b/lib/libnetlink.c
index e9b8c3bd..d068dbe2 100644
--- a/lib/libnetlink.c
+++ b/lib/libnetlink.c
@@ -686,7 +686,7 @@ static int rtnl_dump_done(struct nlmsghdr *h,
      if (len < 0) {
              errno = -len;

-             if (a->errhndlr(h, a->arg2) & RTNL_SUPPRESS_NLMSG_DONE_NLERR)
+             if (a->errhndlr && (a->errhndlr(h, a->arg2) & RTNL_SUPPRESS_NLMSG_DONE_NLERR))
                      return 0;

              /* check for any messages returned from kernel */
@@ -729,7 +729,7 @@ static int rtnl_dump_error(const struct rtnl_handle *rth,
                   errno == EOPNOTSUPP))
                      return -1;

-             if (a->errhndlr(h, a->arg2) & RTNL_SUPPRESS_NLMSG_ERROR_NLERR)
+             if (a->errhndlr && (a->errhndlr(h, a->arg2) & RTNL_SUPPRESS_NLMSG_ERROR_NLERR))
                      return 0;

              if (!(rth->flags & RTNL_HANDLE_F_SUPPRESS_NLERR))
that was quick. was about to send the exact same patch :)
so tested as well. thanks!
hah ;)

Thanks for reporting and sorry that I've introduced the issue that
affected you.
Reviewed-by: Roi Dayan <redacted>
Thanks,
Alex
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help