| From b06d072ccc4b1acd0147b17914b7ad1caa1818bb Mon Sep 17 00:00:00 2001 |
| From: Willem de Bruijn <willemb@google.com> |
| Date: Sun, 22 Mar 2020 13:51:13 -0400 |
| Subject: macsec: restrict to ethernet devices |
| |
| Only attach macsec to ethernet devices. |
| |
| Syzbot was able to trigger a KMSAN warning in macsec_handle_frame |
| by attaching to a phonet device. |
| |
| Macvlan has a similar check in macvlan_port_create. |
| |
| v1->v2 |
| - fix commit message typo |
| |
| Reported-by: syzbot <syzkaller@googlegroups.com> |
| Signed-off-by: Willem de Bruijn <willemb@google.com> |
| Signed-off-by: David S. Miller <davem@davemloft.net> |
| --- |
| drivers/net/macsec.c | 3 +++ |
| 1 file changed, 3 insertions(+) |
| |
| --- a/drivers/net/macsec.c |
| +++ b/drivers/net/macsec.c |
| @@ -20,6 +20,7 @@ |
| #include <net/macsec.h> |
| #include <linux/phy.h> |
| #include <linux/byteorder/generic.h> |
| +#include <linux/if_arp.h> |
| |
| #include <uapi/linux/if_macsec.h> |
| |
| @@ -3859,6 +3860,8 @@ static int macsec_newlink(struct net *ne |
| real_dev = __dev_get_by_index(net, nla_get_u32(tb[IFLA_LINK])); |
| if (!real_dev) |
| return -ENODEV; |
| + if (real_dev->type != ARPHRD_ETHER) |
| + return -EINVAL; |
| |
| dev->priv_flags |= IFF_MACSEC; |
| |