nbd: null check for nla_nest_start
authorNavid Emamdoost <navid.emamdoost@gmail.com>
Sun, 18 Feb 2024 04:25:38 +0000 (20:25 -0800)
committerJens Axboe <axboe@kernel.dk>
Sun, 18 Feb 2024 13:01:18 +0000 (06:01 -0700)
nla_nest_start() may fail and return NULL. Insert a check and set errno
based on other call sites within the same source code.

Signed-off-by: Navid Emamdoost <navid.emamdoost@gmail.com>
Reviewed-by: Michal Kubecek <mkubecek@suse.cz>
Fixes: 47d902b90a32 ("nbd: add a status netlink command")
Signed-off-by: Kees Cook <keescook@chromium.org>
Link: https://lore.kernel.org/r/20240218042534.it.206-kees@kernel.org
Signed-off-by: Jens Axboe <axboe@kernel.dk>
drivers/block/nbd.c

index 30ae3cc12e7787ba36a054f3418fd62a4ad6bf7f..d2b422d842b78597654bb7bcf7bb549d767b561e 100644 (file)
@@ -2433,6 +2433,12 @@ static int nbd_genl_status(struct sk_buff *skb, struct genl_info *info)
        }
 
        dev_list = nla_nest_start_noflag(reply, NBD_ATTR_DEVICE_LIST);
+       if (!dev_list) {
+               nlmsg_free(reply);
+               ret = -EMSGSIZE;
+               goto out;
+       }
+
        if (index == -1) {
                ret = idr_for_each(&nbd_index_idr, &status_cb, reply);
                if (ret) {