Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1397338

[PATCH 4.2.y-ckt 02/59] USB: usbip: fix potential out-of-bounds write

From Kamal Mostafa <kamal@canonical.com>
Newsgroups linux.kernel
Subject [PATCH 4.2.y-ckt 02/59] USB: usbip: fix potential out-of-bounds write
Date 2016-05-09 22:20 +0200
Message-ID <rwZOP-48t-15@gated-at.bofh.it> (permalink)
References <rwZvs-3Ct-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


4.2.8-ckt10 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Ignat Korchagin <ignat.korchagin@gmail.com>

commit b348d7dddb6c4fbfc810b7a0626e8ec9e29f7cbb upstream.

Fix potential out-of-bounds write to urb->transfer_buffer
usbip handles network communication directly in the kernel. When receiving a
packet from its peer, usbip code parses headers according to protocol. As
part of this parsing urb->actual_length is filled. Since the input for
urb->actual_length comes from the network, it should be treated as untrusted.
Any entity controlling the network may put any value in the input and the
preallocated urb->transfer_buffer may not be large enough to hold the data.
Thus, the malicious entity is able to write arbitrary data to kernel memory.

Signed-off-by: Ignat Korchagin <ignat.korchagin@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Reference: CVE-2016-3955
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/usb/usbip/usbip_common.c | 11 +++++++++++
 1 file changed, 11 insertions(+)

diff --git a/drivers/usb/usbip/usbip_common.c b/drivers/usb/usbip/usbip_common.c
index facaaf0..e40da77 100644
--- a/drivers/usb/usbip/usbip_common.c
+++ b/drivers/usb/usbip/usbip_common.c
@@ -741,6 +741,17 @@ int usbip_recv_xbuff(struct usbip_device *ud, struct urb *urb)
 	if (!(size > 0))
 		return 0;
 
+	if (size > urb->transfer_buffer_length) {
+		/* should not happen, probably malicious packet */
+		if (ud->side == USBIP_STUB) {
+			usbip_event_add(ud, SDEV_EVENT_ERROR_TCP);
+			return 0;
+		} else {
+			usbip_event_add(ud, VDEV_EVENT_ERROR_TCP);
+			return -EPIPE;
+		}
+	}
+
 	ret = usbip_recv(ud->tcp_socket, urb->transfer_buffer, size);
 	if (ret != size) {
 		dev_err(&urb->dev->dev, "recv xbuf, %d\n", ret);
-- 
2.7.4

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[4.2.y-ckt stable] Linux 4.2.8-ckt10 stable review Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:00 +0200
  [PATCH 4.2.y-ckt 25/59] ARM: SoCFPGA: Fix secondary CPU startup in thumb2 kernel Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:00 +0200
  [PATCH 4.2.y-ckt 57/59] net/mlx5e: Fix MLX5E_100BASE_T define Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:00 +0200
  [PATCH 4.2.y-ckt 53/59] batman-adv: Check skb size before using encapsulated ETH+VLAN header Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:00 +0200
  [PATCH 4.2.y-ckt 04/59] ASoC: dapm: Make sure we have a card when displaying component widgets Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:00 +0200
  [PATCH 4.2.y-ckt 49/59] jme: Do not enable NIC WoL functions on S0 Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:00 +0200
  [PATCH 4.2.y-ckt 19/59] drm/i915: Fix system resume if PCI device remained enabled Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:00 +0200
  [PATCH 4.2.y-ckt 54/59] batman-adv: Fix broadcast/ogm queue limit on a removed interface Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:00 +0200
  [PATCH 4.2.y-ckt 59/59] RDMA/iw_cxgb4: Fix bar2 virt addr calculation for T4 chips Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:00 +0200
  [PATCH 4.2.y-ckt 32/59] EDAC: i7core, sb_edac: Don't return NOTIFY_BAD from mce_decoder callback Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:00 +0200
  [PATCH 4.2.y-ckt 55/59] mm: update min_free_kbytes from khugepaged after core initialization Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:00 +0200
  [PATCH 4.2.y-ckt 58/59] cxgbi: fix uninitialized flowi6 Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:00 +0200
  [PATCH 4.2.y-ckt 56/59] ARM: EXYNOS: Properly skip unitialized parent clock in power domain on Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:00 +0200
  [PATCH 4.2.y-ckt 24/59] drm/radeon: fix vertical bars appear on monitor (v2) Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:10 +0200
  [PATCH 4.2.y-ckt 33/59] powerpc: Fix bad inline asm constraint in create_zero_mask() Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:10 +0200
  [PATCH 4.2.y-ckt 42/59] x86/sysfb_efi: Fix valid BAR address range check Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:10 +0200
  [PATCH 4.2.y-ckt 48/59] parisc: fix a bug when syscall number of tracee is __NR_Linux_syscalls Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:10 +0200
  [PATCH 4.2.y-ckt 41/59] ARC: Add missing io barriers to io{read,write}{16,32}be() Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:10 +0200
  [PATCH 4.2.y-ckt 45/59] writeback: Fix performance regression in wb_over_bg_thresh() Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:10 +0200
  [PATCH 4.2.y-ckt 35/59] drm/amdgpu: set metadata pointer to NULL after freeing. Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:10 +0200
  [PATCH 4.2.y-ckt 34/59] Minimal fix-up of bad hashing behavior of hash_64() Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:10 +0200
  [PATCH 4.2.y-ckt 21/59] drm/i915: Fix eDP low vswing for Broadwell Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:10 +0200
  [PATCH 4.2.y-ckt 44/59] propogate_mnt: Handle the first propogated copy being a slave Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:10 +0200
  [PATCH 4.2.y-ckt 51/59] net/mlx4_en: fix spurious timestamping callbacks Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:10 +0200
  [PATCH 4.2.y-ckt 30/59] mm/huge_memory: replace VM_NO_THP VM_BUG_ON with actual VMA check Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:10 +0200
  [PATCH 4.2.y-ckt 26/59] x86/irq: Fix a race in x86_vector_free_irqs() Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:10 +0200
  [PATCH 4.2.y-ckt 43/59] fs/pnode.c: treat zero mnt_group_id-s as unequal Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:10 +0200
  [PATCH 4.2.y-ckt 39/59] MAINTAINERS: Remove asterisk from EFI directory names Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:10 +0200
  [PATCH 4.2.y-ckt 28/59] ARM: cpuidle: Pass on arm_cpuidle_suspend()'s return value Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:10 +0200
  [PATCH 4.2.y-ckt 29/59] IB/security: Restrict use of the write() interface Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:10 +0200
  [PATCH 4.2.y-ckt 47/59] x86/tsc: Read all ratio bits from MSR_PLATFORM_INFO Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:10 +0200
  [PATCH 4.2.y-ckt 22/59] drm/i915: Make RPS EI/thresholds multiple of 25 on SNB-BDW Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:10 +0200
  [PATCH 4.2.y-ckt 52/59] batman-adv: Reduce refcnt of removed router when updating route Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:10 +0200
  [PATCH 4.2.y-ckt 46/59] mm, cma: prevent nr_isolated_* counters from going negative Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:10 +0200
  [PATCH 4.2.y-ckt 31/59] mm: vmscan: reclaim highmem zone if buffer_heads is over limit Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:10 +0200
  [PATCH 4.2.y-ckt 50/59] jme: Fix device PM wakeup API usage Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:10 +0200
  [PATCH 4.2.y-ckt 36/59] tracing: Don't display trigger file for events that can't be enabled Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:10 +0200
  [PATCH 4.2.y-ckt 38/59] drm/amdgpu: make sure vertical front porch is at least 1 Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:10 +0200
  [PATCH 4.2.y-ckt 27/59] x86/apic: Handle zero vector gracefully in clear_vector_irq() Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:10 +0200
  [PATCH 4.2.y-ckt 40/59] ACPICA: Dispatcher: Update thread ID for recursive method calls Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:10 +0200
  [PATCH 4.2.y-ckt 18/59] cxl: Keep IRQ mappings on context teardown Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:20 +0200
  [PATCH 4.2.y-ckt 02/59] USB: usbip: fix potential out-of-bounds write Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:20 +0200
  [PATCH 4.2.y-ckt 07/59] iio: ak8975: fix maybe-uninitialized warning Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:20 +0200
  [PATCH 4.2.y-ckt 12/59] USB: serial: cp210x: add Straizona Focusers device ids Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:20 +0200
  [PATCH 4.2.y-ckt 13/59] [media] v4l2-dv-timings.h: fix polarity for 4k formats Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:20 +0200
  [PATCH 4.2.y-ckt 14/59] ALSA: hda - Add dock support for ThinkPad X260 Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:20 +0200
  [PATCH 4.2.y-ckt 05/59] ath9k: ar5008_hw_cmn_spur_mitigate: add missing mask_m & mask_p initialisation Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:20 +0200
  [PATCH 4.2.y-ckt 09/59] i2c: exynos5: Fix possible ABBA deadlock by keeping I2C clock prepared Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:20 +0200
  [PATCH 4.2.y-ckt 20/59] drm/i915/ddi: Fix eDP VDD handling during booting and suspend/resume Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:20 +0200
  [PATCH 4.2.y-ckt 06/59] iio: ak8975: Fix NULL pointer exception on early interrupt Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:20 +0200
  [PATCH 4.2.y-ckt 01/59] x86/mm/32: Enable full randomization on i386 and X86_32 Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:20 +0200
  [PATCH 4.2.y-ckt 16/59] drm/dp/mst: Get validated port ref in drm_dp_update_payload_part1() Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:20 +0200
  [PATCH 4.2.y-ckt 11/59] USB: serial: cp210x: add ID for Link ECU Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:20 +0200
  [PATCH 4.2.y-ckt 10/59] efi: Fix out-of-bounds read in variable_matches() Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:20 +0200
  [PATCH 4.2.y-ckt 15/59] workqueue: fix ghost PENDING flag while doing MQ IO Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:20 +0200
  [PATCH 4.2.y-ckt 03/59] ASoC: rt5640: Correct the digital interface data select Kamal Mostafa <kamal@canonical.com> - 2016-05-09 22:20 +0200

csiph-web