Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1461939 > unrolled thread

[PATCH 3.16 170/305] usb: gadget: avoid exposing kernel stack

Started byBen Hutchings <ben@decadent.org.uk>
First post2016-08-14 13:30 +0200
Last post2016-08-14 13:30 +0200
Articles 1 — 1 participant

Back to article view | Back to linux.kernel

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  [PATCH 3.16 170/305] usb: gadget: avoid exposing kernel stack Ben Hutchings <ben@decadent.org.uk> - 2016-08-14 13:30 +0200

#1461939 — [PATCH 3.16 170/305] usb: gadget: avoid exposing kernel stack

FromBen Hutchings <ben@decadent.org.uk>
Date2016-08-14 13:30 +0200
Subject[PATCH 3.16 170/305] usb: gadget: avoid exposing kernel stack
Message-ID<s61M7-7m3-71@gated-at.bofh.it>
3.16.37-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Heinrich Schuchardt <xypron.glpk@gmx.de>

commit ffeee83aa0461992e8a99a59db2df31933e60362 upstream.

Function in_rq_cur copies random bytes from the stack.
Zero the memory instead.

Fixes: 132fcb460839 ("usb: gadget: Add Audio Class 2.0 Driver")
Signed-off-by: Heinrich Schuchardt <xypron.glpk@gmx.de>
Signed-off-by: Felipe Balbi <felipe.balbi@linux.intel.com>
[bwh: Backported to 3.16: adjust filename]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/usb/gadget/f_uac2.c | 1 +
 1 file changed, 1 insertion(+)

--- a/drivers/usb/gadget/f_uac2.c
+++ b/drivers/usb/gadget/f_uac2.c
@@ -1153,6 +1153,7 @@ in_rq_cur(struct usb_function *fn, const
 
 	if (control_selector == UAC2_CS_CONTROL_SAM_FREQ) {
 		struct cntrl_cur_lay3 c;
+		memset(&c, 0, sizeof(struct cntrl_cur_lay3));
 
 		if (entity_id == USB_IN_CLK_ID)
 			c.dCUR = p_srate;

[toc] | [standalone]


Back to top | Article view | linux.kernel


csiph-web