sctp: fix error return code in sctp_sendmsg_new_asoc()
authorWei Yongjun <weiyongjun1@huawei.com>
Tue, 13 Mar 2018 03:03:30 +0000 (03:03 +0000)
committerDavid S. Miller <davem@davemloft.net>
Tue, 13 Mar 2018 14:45:11 +0000 (10:45 -0400)
Return error code -EINVAL in the address len check error handling
case since 'err' can be overwrite to 0 by 'err = sctp_verify_addr()'
in the for loop.

Fixes: 2c0dbaa0c43d ("sctp: add support for SCTP_DSTADDRV4/6 Information for sendmsg")
Signed-off-by: Wei Yongjun <weiyongjun1@huawei.com>
Acked-by: Neil Horman <nhorman@tuxdriver.com>
Reviewed-by: Xin Long <lucien.xin@gmail.com>
Acked-by: Neil Horman <nhorman@tuxdriver.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
net/sctp/socket.c

index 7d3476a4860d47958e7b5b0b3d4c69cb7306affd..af5cf29b0c659c2fc3f67473578b09431fe272ab 100644 (file)
@@ -1677,7 +1677,7 @@ static int sctp_sendmsg_new_asoc(struct sock *sk, __u16 sflags,
        struct sctp_association *asoc;
        enum sctp_scope scope;
        struct cmsghdr *cmsg;
-       int err = -EINVAL;
+       int err;
 
        *tp = NULL;
 
@@ -1761,16 +1761,20 @@ static int sctp_sendmsg_new_asoc(struct sock *sk, __u16 sflags,
                memset(daddr, 0, sizeof(*daddr));
                dlen = cmsg->cmsg_len - sizeof(struct cmsghdr);
                if (cmsg->cmsg_type == SCTP_DSTADDRV4) {
-                       if (dlen < sizeof(struct in_addr))
+                       if (dlen < sizeof(struct in_addr)) {
+                               err = -EINVAL;
                                goto free;
+                       }
 
                        dlen = sizeof(struct in_addr);
                        daddr->v4.sin_family = AF_INET;
                        daddr->v4.sin_port = htons(asoc->peer.port);
                        memcpy(&daddr->v4.sin_addr, CMSG_DATA(cmsg), dlen);
                } else {
-                       if (dlen < sizeof(struct in6_addr))
+                       if (dlen < sizeof(struct in6_addr)) {
+                               err = -EINVAL;
                                goto free;
+                       }
 
                        dlen = sizeof(struct in6_addr);
                        daddr->v6.sin6_family = AF_INET6;