Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1703821

Re: drivers/s390/char/keyboard.c NULL pointer reference

From Heiko Carstens <heiko.carstens@de.ibm.com>
Newsgroups linux.kernel
Subject Re: drivers/s390/char/keyboard.c NULL pointer reference
Date 2017-08-04 11:30 +0200
Message-ID <uaH5E-5ax-21@gated-at.bofh.it> (permalink)
References <uaoPn-Jx-7@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Thu, Aug 03, 2017 at 09:57:38PM +0800, sohu0106 wrote:
> 
> 
> Local users able to send the NULL arg argument to kbd_ioctl(), which could cause kernel crash
> 
> 
> 
> 
> diff --git a/keyboard.c 
> b/keyboard.c
> index ba0e4f9..3ec16b1 100644
> --- a/keyboard.c
> +++ b/keyboard.c
> @@ -456,6 +456,8 @@ int kbd_ioctl(struct kbd_data *kbd, unsigned int cmd, unsigned long arg)
>         int perm;
>  
>         argp = (void __user *)arg;
> +       if( !argp )
> +               return -EFAULT;

This doesn't make sense as well. All uaccess functions are able to handle
NULL pointers within user space.

Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

drivers/s390/char/keyboard.c NULL pointer reference sohu0106 <sohu0106@126.com> - 2017-08-03 16:00 +0200
  Re: drivers/s390/char/keyboard.c NULL pointer reference Heiko Carstens <heiko.carstens@de.ibm.com> - 2017-08-04 11:30 +0200
    Re:Re: drivers/s390/char/keyboard.c NULL pointer reference sohu0106 <sohu0106@126.com> - 2017-08-05 03:50 +0200
      Re: Re: drivers/s390/char/keyboard.c NULL pointer reference Heiko Carstens <heiko.carstens@de.ibm.com> - 2017-08-05 10:00 +0200

csiph-web