[AF_NETLINK]: Fix DoS in netlink_rcv_skb()

From: Martin Murray <murrayma@citi.umich.edu>

Sanity check nlmsg_len during netlink_rcv_skb. An nlmsg_len == 0 can
cause infinite loop in kernel, effectively DoSing machine. Noted by
Matin Murray.

Signed-off-by: Chris Wright <chrisw@sous-sol.org>
Signed-off-by: David S. Miller <davem@davemloft.net>

authored by

Martin Murray and committed by
David S. Miller
ad8e4b75 babbdb1a

+1 -1
+1 -1
net/netlink/af_netlink.c
··· 1422 1422 while (skb->len >= nlmsg_total_size(0)) { 1423 1423 nlh = (struct nlmsghdr *) skb->data; 1424 1424 1425 - if (skb->len < nlh->nlmsg_len) 1425 + if (nlh->nlmsg_len < NLMSG_HDRLEN || skb->len < nlh->nlmsg_len) 1426 1426 return 0; 1427 1427 1428 1428 total_len = min(NLMSG_ALIGN(nlh->nlmsg_len), skb->len);