This is a note to let you know that I've just added the patch titled net: ieee802154: fix nl802154 del llsec dev to the 5.11-stable tree which can be found at: http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary The filename of the patch is: net-ieee802154-fix-nl802154-del-llsec-dev.patch and it can be found in the queue-5.11 subdirectory. If you, or anyone else, feels it should not be added to the stable tree, please let <stable@xxxxxxxxxxxxxxx> know about it. >From 3d1eac2f45585690d942cf47fd7fbd04093ebd1b Mon Sep 17 00:00:00 2001 From: Alexander Aring <aahringo@xxxxxxxxxx> Date: Sun, 21 Feb 2021 12:43:19 -0500 Subject: net: ieee802154: fix nl802154 del llsec dev From: Alexander Aring <aahringo@xxxxxxxxxx> commit 3d1eac2f45585690d942cf47fd7fbd04093ebd1b upstream. This patch fixes a nullpointer dereference if NL802154_ATTR_SEC_DEVICE is not set by the user. If this is the case nl802154 will return -EINVAL. Reported-by: syzbot+d946223c2e751d136c94@xxxxxxxxxxxxxxxxxxxxxxxxx Signed-off-by: Alexander Aring <aahringo@xxxxxxxxxx> Link: https://lore.kernel.org/r/20210221174321.14210-2-aahringo@xxxxxxxxxx Signed-off-by: Stefan Schmidt <stefan@xxxxxxxxxxxxxxxxxx> Signed-off-by: Greg Kroah-Hartman <gregkh@xxxxxxxxxxxxxxxxxxx> --- net/ieee802154/nl802154.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) --- a/net/ieee802154/nl802154.c +++ b/net/ieee802154/nl802154.c @@ -1758,7 +1758,8 @@ static int nl802154_del_llsec_dev(struct struct nlattr *attrs[NL802154_DEV_ATTR_MAX + 1]; __le64 extended_addr; - if (nla_parse_nested_deprecated(attrs, NL802154_DEV_ATTR_MAX, info->attrs[NL802154_ATTR_SEC_DEVICE], nl802154_dev_policy, info->extack)) + if (!info->attrs[NL802154_ATTR_SEC_DEVICE] || + nla_parse_nested_deprecated(attrs, NL802154_DEV_ATTR_MAX, info->attrs[NL802154_ATTR_SEC_DEVICE], nl802154_dev_policy, info->extack)) return -EINVAL; if (!attrs[NL802154_DEV_ATTR_EXTENDED_ADDR]) Patches currently in stable-queue which might be from aahringo@xxxxxxxxxx are queue-5.11/net-ieee802154-fix-nl802154-del-llsec-devkey.patch queue-5.11/net-ieee802154-fix-nl802154-del-llsec-key.patch queue-5.11/net-ieee802154-forbid-monitor-for-del-llsec-seclevel.patch queue-5.11/net-ieee802154-fix-nl802154-add-llsec-key.patch queue-5.11/net-ieee802154-forbid-monitor-for-set-llsec-params.patch queue-5.11/net-ieee802154-nl-mac-fix-check-on-panid.patch queue-5.11/net-mac802154-fix-general-protection-fault.patch queue-5.11/net-ieee802154-fix-nl802154-del-llsec-dev.patch queue-5.11/net-ieee802154-stop-dump-llsec-params-for-monitors.patch