Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1467189

[PATCH 1/1] drm: avoid exposing kernel stack in compat_drm_getstats

From Heinrich Schuchardt <xypron.glpk@gmx.de>
Newsgroups linux.kernel
Subject [PATCH 1/1] drm: avoid exposing kernel stack in compat_drm_getstats
Date 2016-08-21 20:00 +0200
Message-ID <s8Fcl-3qf-1@gated-at.bofh.it> (permalink)
Organization linux.* mail to news gateway

Show all headers | View raw


The C standard does not specify the size of the integer used
to store an enum. Hence in structure drm_stats32_t alignment
bytes may exist.

To avoid exposing bytes from the kernel stack it is
necessary to initialize variable s32 completely.

Signed-off-by: Heinrich Schuchardt <xypron.glpk@gmx.de>
---
 drivers/gpu/drm/drm_ioc32.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/gpu/drm/drm_ioc32.c b/drivers/gpu/drm/drm_ioc32.c
index 57676f8..32a489b 100644
--- a/drivers/gpu/drm/drm_ioc32.c
+++ b/drivers/gpu/drm/drm_ioc32.c
@@ -346,6 +346,7 @@ static int compat_drm_getstats(struct file *file, unsigned int cmd,
 	struct drm_stats __user *stats;
 	int i, err;
 
+	memset(&s32, 0, sizeof(drm_stats32_t));
 	stats = compat_alloc_user_space(sizeof(*stats));
 	if (!stats)
 		return -EFAULT;
-- 
2.1.4

Back to linux.kernel | Previous | NextNext in thread | Find similar | Unroll thread


Thread

[PATCH 1/1] drm: avoid exposing kernel stack in compat_drm_getstats Heinrich Schuchardt <xypron.glpk@gmx.de> - 2016-08-21 20:00 +0200
  Re: [PATCH 1/1] drm: avoid exposing kernel stack in  compat_drm_getstats Daniel Vetter <daniel@ffwll.ch> - 2016-08-22 09:30 +0200
    Re: [PATCH 1/1] drm: avoid exposing kernel stack in compat_drm_getstats Jani Nikula <jani.nikula@linux.intel.com> - 2016-08-22 10:40 +0200

csiph-web