Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1715183 > unrolled thread
| Started by | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| First post | 2017-08-18 16:30 +0200 |
| Last post | 2017-08-18 17:00 +0200 |
| Articles | 16 — 2 participants |
Back to article view | Back to linux.kernel
[PATCH 3.2 00/59] 3.2.92-rc1 review Ben Hutchings <ben@decadent.org.uk> - 2017-08-18 16:30 +0200
[PATCH 3.2 35/59] [media] dw2102: limit messages to buffer size Ben Hutchings <ben@decadent.org.uk> - 2017-08-18 16:30 +0200
[PATCH 3.2 24/59] PCI: Fix pci_mmap_fits() for HAVE_PCI_RESOURCE_TO_USER platforms Ben Hutchings <ben@decadent.org.uk> - 2017-08-18 16:30 +0200
[PATCH 3.2 17/59] [media] gspca: konica: add missing endpoint sanity check Ben Hutchings <ben@decadent.org.uk> - 2017-08-18 16:30 +0200
[PATCH 3.2 13/59] [media] mceusb: fix NULL-deref at probe Ben Hutchings <ben@decadent.org.uk> - 2017-08-18 16:30 +0200
[PATCH 3.2 20/59] [media] cx231xx-cards: fix NULL-deref at probe Ben Hutchings <ben@decadent.org.uk> - 2017-08-18 16:30 +0200
[PATCH 3.2 32/59] [media] ttusb2: limit messages to buffer size Ben Hutchings <ben@decadent.org.uk> - 2017-08-18 16:30 +0200
[PATCH 3.2 02/59] [media] pvrusb2: reduce stack usage pvr2_eeprom_analyze() Ben Hutchings <ben@decadent.org.uk> - 2017-08-18 16:30 +0200
[PATCH 3.2 22/59] [media] cx231xx-audio: fix NULL-deref at probe Ben Hutchings <ben@decadent.org.uk> - 2017-08-18 16:30 +0200
[PATCH 3.2 04/59] ath9k_htc: Add PID/VID for a Ubiquiti WiFiStation Ben Hutchings <ben@decadent.org.uk> - 2017-08-18 16:30 +0200
[PATCH 3.2 10/59] zd1211rw: fix NULL-deref at probe Ben Hutchings <ben@decadent.org.uk> - 2017-08-18 16:30 +0200
[PATCH 3.2 27/59] PCI: Ignore write combining when mapping I/O port space Ben Hutchings <ben@decadent.org.uk> - 2017-08-18 16:30 +0200
[PATCH 3.2 06/59] ath9k_htc: Add new USB ID Ben Hutchings <ben@decadent.org.uk> - 2017-08-18 16:30 +0200
[PATCH 3.2 25/59] [media] digitv: limit messages to buffer size Ben Hutchings <ben@decadent.org.uk> - 2017-08-18 16:30 +0200
[PATCH 3.2 18/59] [media] usbvision: fix NULL-deref at probe Ben Hutchings <ben@decadent.org.uk> - 2017-08-18 16:30 +0200
Re: [PATCH 3.2 00/59] 3.2.92-rc1 review Guenter Roeck <linux@roeck-us.net> - 2017-08-18 17:00 +0200
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2017-08-18 16:30 +0200 |
| Subject | [PATCH 3.2 00/59] 3.2.92-rc1 review |
| Message-ID | <ufPlU-4d0-25@gated-at.bofh.it> |
This is the start of the stable review cycle for the 3.2.92 release.
There are 59 patches in this series, which will be posted as responses
to this one. If anyone has any issues with these being applied, please
let me know.
Responses should be made by Mon Aug 21 18:00:00 UTC 2017.
Anything received after that time might be too late.
A combined patch relative to 3.2.91 will be posted as an additional
response to this. A shortlog and diffstat can be found below.
Ben.
-------------
Ajay Kaher (1):
USB: Proper handling of Race Condition when two USB class drivers try to call init_usb_class simultaneously
[2f86a96be0ccb1302b7eee7855dbee5ce4dc5dfb]
Alexander Tsoy (1):
ath9k_htc: add device ID for Toshiba WLM-20U2/GN-1080
[aea57edf80c6e96d6dc24757599396af99c02b19]
Alexey Brodkin (1):
usb: Make sure usb/phy/of gets built-in
[3d6159640da9c9175d1ca42f151fc1a14caded59]
Alexey Khoroshilov (1):
[media] cx231xx: fix double free and leaks on failure path in cx231xx_usb_probe()
[256d013a9bcc9a39b2e4b34ab19219bd054cf270]
Alyssa Milburn (4):
[media] digitv: limit messages to buffer size
[821117dc21083a99dd99174c10848d70ff43de29]
[media] dw2102: limit messages to buffer size
[950e252cb469f323740d78e4907843acef89eedb]
[media] ttusb2: limit messages to buffer size
[a12b8ab8c5ff7ccd7b107a564743507c850a441d]
[media] zr364xx: enforce minimum size when reading header
[ee0fe833d96793853335844b6d99fb76bd12cbeb]
Andrey Ryabinin (1):
drm/i915: fix use-after-free in page_flip_completed()
[05c41f926fcc7ef838c80a6a99d84f67b4e0b824]
Arnd Bergmann (2):
[media] pvrusb2: reduce stack usage pvr2_eeprom_analyze()
[6830733d53a4517588e56227b9c8538633f0c496]
fbdev: sti: don't select CONFIG_VT
[34bf129a7f068e3108dbb051b4b05674e2a270e7]
Ashish Kalra (1):
x86/boot: Fix BSS corruption/overwrite bug in early x86 kernel startup
[d594aa0277e541bb997aef0bc0a55172d8138340]
Bjorn Helgaas (1):
PCI: Ignore write combining when mapping I/O port space
[3a92c319c44a7bcee9f48dff9d97d001943b54c6]
Christoph Hellwig (1):
libata: reject passthrough WRITE SAME requests
[c6ade20f5e50e188d20b711a618b20dd1d50457e]
Christophe Leroy (1):
net: ethernet: ucc_geth: fix MEM_PART_MURAM mode
[8b8642af15ed14b9a7a34d3401afbcc274533e13]
Cong Wang (1):
mqueue: fix a use-after-free in sys_mq_notify()
[f991af3daabaecff34684fd51fac80319d1baad1]
Craig Gallek (1):
ip6_tunnel: Fix missing tunnel encapsulation limit option
[89a23c8b528bd2c89f3981573d6cd7d23840c8a6]
Dan Carpenter (2):
[media] dw2102: some missing unlocks on error
[324ed533bf0b23c309b805272c4ffcc5d51493a6]
cifs: small underflow in cnvrtDosUnixTm()
[564277eceeca01e02b1ef3e141cfb939184601b4]
David S. Miller (1):
ipv6: Need to export ipv6_push_frag_opts for tunneling now.
[5b8481fa42ac58484d633b558579e302aead64c1]
David Woodhouse (3):
PCI: Fix another sanity check bug in /proc/pci mmap
[17caf56731311c9596e7d38a70c88fcb6afa6a1b]
PCI: Fix pci_mmap_fits() for HAVE_PCI_RESOURCE_TO_USER platforms
[6bccc7f426abd640f08d8c75fb22f99483f201b4]
PCI: Only allow WC mmap on prefetchable resources
[cef4d02305a06be581bb7f4353446717a1b319ec]
Dmitry Tunin (1):
ath9k_htc: Add support of AirTies 1eda:2315 AR9271 device
[16ff1fb0e32f76a5d285a6f23b82d21aa52813c6]
Eric Dumazet (1):
tcp: fix wraparound issue in tcp_lp
[a9f11f963a546fea9144f6a6d1a307e814a387e7]
Frank Schaefer (1):
[media] ov2640: fix vflip control
[7f140fc2064bcd23e0490d8210650e2ef21c1c89]
Guenter Roeck (2):
usb: hub: Do not attempt to autosuspend disconnected devices
[f5cccf49428447dfbc9edb7a04bb8fc316269781]
usb: hub: Fix error loop seen after hub communication errors
[245b2eecee2aac6fdc77dcafaa73c33f9644c3c7]
Jason A. Donenfeld (1):
padata: free correct variable
[07a77929ba672d93642a56dc2255dd21e6e2290b]
Johan Hovold (8):
[media] cx231xx-audio: fix NULL-deref at probe
[65f921647f4c89a2068478c89691f39b309b58f7]
[media] cx231xx-audio: fix init error path
[fff1abc4d54e469140a699612b4db8d6397bfcba]
[media] cx231xx-cards: fix NULL-deref at probe
[0cd273bb5e4d1828efaaa8dfd11b7928131ed149]
[media] gspca: konica: add missing endpoint sanity check
[aa58fedb8c7b6cf2f05941d238495f9e2f29655c]
[media] mceusb: fix NULL-deref at probe
[03eb2a557ed552e920a0942b774aaf931596eec1]
[media] usbvision: fix NULL-deref at probe
[eacb975b48272f54532b62f515a3cf7eefa35123]
ath9k_htc: fix NULL-deref at probe
[ebeb36670ecac36c179b5fb5d5c88ff03ba191ec]
zd1211rw: fix NULL-deref at probe
[ca260ece6a57dc7d751e0685f51fa2c55d851873]
Josh Boyer (1):
[media] ttusb2: Don't use stack variables for DMA
[ff17999184ed13829bc14c3be412d980173dff40]
Laura Abbott (1):
x86/mm/32: Set the '__vmalloc_start_set' flag in initmem_init()
[861ce4a3244c21b0af64f880d5bfe5e6e2fb9e4a]
Leon Nardella (1):
ath9k_htc: Add new USB ID
[0088d27b78f2c0118aee82923269518616481ea0]
Liping Zhang (1):
netfilter: ctnetlink: make it safer when updating ct->status
[53b56da83d7899de375a9de153fd7f5397de85e6]
Lukas Wunner (1):
PCI: Freeze PME scan before suspending devices
[ea00353f36b64375518662a8ad15e39218a1f324]
Masaki TAGAWA (1):
ath9k_htc: Add device ID for Buffalo WLI-UV-AG300P
[98f99eeae98047bc195bcc7510eae4f0cf3658a0]
Mauro Carvalho Chehab (1):
[media] dw2102: Don't use dynamic static allocation
[0065a79a8698a953e4b201c5fce8db8940530578]
Michael J. Ruhl (2):
IB/core: For multicast functions, verify that LIDs are multicast LIDs
[8561eae60ff9417a50fa1fb2b83ae950dc5c1e21]
IB/core: If the MGID/MLID pair is not on the list return an error
[20c7840a77ddcb2ed2fbd66e8197db2868495751]
Michael Trimarchi (1):
power: supply: pda_power: move from timer to delayed_work
[633e8799ddc09431be2744c4a1efdbda13af2b0b]
Mohammed Shafi Shajakhan (1):
ath9k_htc: Add PID/VID for a Ubiquiti WiFiStation
[763cbac07674a648f1377b21ca66f577c103fa9a]
Peter Chen (1):
usb: host: xhci: print correct command ring address
[6fc091fb0459ade939a795bfdcaf645385b951d4]
Richard Weinberger (1):
um: Fix PTRACE_POKEUSER on x86_64
[9abc74a22d85ab29cef9896a2582a530da7e79bf]
Sabrina Dubroca (1):
ipv6: avoid overflow of offset in ip6_find_1stfragopt
[6399f1fae4ec29fab5ec76070435555e256ca3a6]
Stefan Assmann (1):
PCI: Disable boot interrupt quirk for ASUS M2N-LR
[c4e649b09f55595e6df6da5465a5b3cfc93557c1]
Steve French (1):
Set unicode flag on cifs echo request to avoid Mac error
[26c9cb668c7fbf9830516b75d8bee70b699ed449]
Sujith Manoharan (1):
ath9k_htc: Add Panasonic N5HBZ0000055 device id
[d90b570898f7cc3dd0b26d4e646f464408b04022]
Szymon Janc (1):
Bluetooth: Fix user channel for 32bit userspace on 64bit kernel
[ab89f0bdd63a3721f7cd3f064f39fc4ac7ca14d4]
Takatoshi Akiyama (1):
serial: sh-sci: Fix panic when serial console and DMA are enabled
[3c9101766b502a0163d1d437fada5801cf616be2]
Thomas Gleixner (1):
timerfd: Protect the might cancel mechanism proper
[1e38da300e1e395a15048b0af1e5305bd91402f6]
Tobias Herzog (1):
cdc-acm: fix possible invalid access when processing notification
[1bb9914e1730417d530de9ed37e59efdc647146b]
Willem de Bruijn (1):
packet: fix tp_reserve race in packet_set_ring
[c27927e372f0785f3303e8fad94b85945e2c97b7]
Makefile | 4 +-
arch/powerpc/include/asm/qe.h | 1 +
arch/x86/boot/boot.h | 2 +-
arch/x86/mm/numa_32.c | 1 +
arch/x86/um/ptrace_64.c | 2 +-
drivers/Makefile | 1 +
drivers/ata/libata-scsi.c | 8 ++
drivers/gpu/drm/i915/intel_display.c | 4 +-
drivers/infiniband/core/uverbs_cmd.c | 13 +-
drivers/infiniband/core/verbs.c | 8 +-
drivers/media/dvb/dvb-usb/digitv.c | 4 +
drivers/media/dvb/dvb-usb/dw2102.c | 170 ++++++++++++++++++++++--
drivers/media/dvb/dvb-usb/ttusb2.c | 36 ++++-
drivers/media/rc/mceusb.c | 4 +-
drivers/media/video/cx231xx/cx231xx-audio.c | 41 ++++--
drivers/media/video/cx231xx/cx231xx-cards.c | 156 ++++++++++++++--------
drivers/media/video/gspca/konica.c | 3 +
drivers/media/video/ov2640.c | 6 +-
drivers/media/video/pvrusb2/pvrusb2-eeprom.c | 13 +-
drivers/media/video/usbvision/usbvision-video.c | 9 +-
drivers/media/video/zr364xx.c | 8 ++
drivers/net/ethernet/freescale/ucc_geth.c | 8 +-
drivers/net/wireless/ath/ath9k/hif_usb.c | 12 ++
drivers/net/wireless/zd1211rw/zd_usb.c | 3 +
drivers/pci/pci-sysfs.c | 10 +-
drivers/pci/pci.c | 9 +-
drivers/pci/proc.c | 20 ++-
drivers/pci/quirks.c | 24 ++++
drivers/power/pda_power.c | 44 +++---
drivers/tty/serial/sh-sci.c | 10 +-
drivers/usb/class/cdc-acm.c | 13 +-
drivers/usb/core/driver.c | 21 +++
drivers/usb/core/file.c | 9 +-
drivers/usb/core/hub.c | 11 +-
drivers/usb/host/xhci-mem.c | 2 +-
drivers/video/Kconfig | 2 -
drivers/video/Makefile | 1 +
fs/cifs/cifssmb.c | 3 +
fs/cifs/netmisc.c | 6 +-
fs/timerfd.c | 17 ++-
include/linux/netfilter/nf_conntrack_common.h | 9 ++
ipc/mqueue.c | 4 +-
kernel/padata.c | 2 +-
net/bluetooth/hci_sock.c | 3 +-
net/ipv4/tcp_lp.c | 6 +-
net/ipv6/exthdrs.c | 2 +-
net/ipv6/ip6_output.c | 8 +-
net/ipv6/ip6_tunnel.c | 4 +-
net/netfilter/nf_conntrack_netlink.c | 27 +++-
net/packet/af_packet.c | 13 +-
50 files changed, 607 insertions(+), 190 deletions(-)
--
Ben Hutchings
Reality is just a crutch for people who can't handle science fiction.
[toc] | [next] | [standalone]
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2017-08-18 16:30 +0200 |
| Subject | [PATCH 3.2 35/59] [media] dw2102: limit messages to buffer size |
| Message-ID | <ufQrF-4YI-37@gated-at.bofh.it> |
| In reply to | #1715183 |
3.2.92-rc1 review patch. If anyone has any objections, please let me know.
------------------
From: Alyssa Milburn <amilburn@zall.org>
commit 950e252cb469f323740d78e4907843acef89eedb upstream.
Otherwise the i2c transfer functions can read or write beyond the end of
stack or heap buffers.
Signed-off-by: Alyssa Milburn <amilburn@zall.org>
Signed-off-by: Mauro Carvalho Chehab <mchehab@s-opensource.com>
[bwh: Backported to 3.2:
- Use obuf instead of state->data
- Adjust filename, context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
drivers/media/dvb/dvb-usb/dw2102.c | 54 ++++++++++++++++++++++++++++++++++++++
1 file changed, 54 insertions(+)
--- a/drivers/media/dvb/dvb-usb/dw2102.c
+++ b/drivers/media/dvb/dvb-usb/dw2102.c
@@ -234,6 +234,20 @@ static int dw2102_serit_i2c_transfer(str
switch (num) {
case 2:
+ if (msg[0].len != 1) {
+ warn("i2c rd: len=%d is not 1!\n",
+ msg[0].len);
+ num = -EOPNOTSUPP;
+ break;
+ }
+
+ if (2 + msg[1].len > sizeof(buf6)) {
+ warn("i2c rd: len=%d is too big!\n",
+ msg[1].len);
+ num = -EOPNOTSUPP;
+ break;
+ }
+
/* read si2109 register by number */
buf6[0] = msg[0].addr << 1;
buf6[1] = msg[0].len;
@@ -249,6 +263,13 @@ static int dw2102_serit_i2c_transfer(str
case 1:
switch (msg[0].addr) {
case 0x68:
+ if (2 + msg[0].len > sizeof(buf6)) {
+ warn("i2c wr: len=%d is too big!\n",
+ msg[0].len);
+ num = -EOPNOTSUPP;
+ break;
+ }
+
/* write to si2109 register */
buf6[0] = msg[0].addr << 1;
buf6[1] = msg[0].len;
@@ -292,6 +313,13 @@ static int dw2102_earda_i2c_transfer(str
/* first write first register number */
u8 ibuf[MAX_XFER_SIZE], obuf[3];
+ if (2 + msg[0].len != sizeof(obuf)) {
+ warn("i2c rd: len=%d is not 1!\n",
+ msg[0].len);
+ ret = -EOPNOTSUPP;
+ goto unlock;
+ }
+
if (2 + msg[1].len > sizeof(ibuf)) {
warn("i2c rd: len=%d is too big!\n",
msg[1].len);
@@ -492,6 +520,12 @@ static int dw3101_i2c_transfer(struct i2
/* first write first register number */
u8 ibuf[MAX_XFER_SIZE], obuf[3];
+ if (2 + msg[0].len != sizeof(obuf)) {
+ warn("i2c rd: len=%d is not 1!\n",
+ msg[0].len);
+ ret = -EOPNOTSUPP;
+ goto unlock;
+ }
if (2 + msg[1].len > sizeof(ibuf)) {
warn("i2c rd: len=%d is too big!\n",
msg[1].len);
@@ -718,6 +752,13 @@ static int su3000_i2c_transfer(struct i2
msg[0].buf[0] = ibuf[1];
break;
default:
+ if (3 + msg[0].len > sizeof(obuf)) {
+ warn("i2c wr: len=%d is too big!\n",
+ msg[0].len);
+ num = -EOPNOTSUPP;
+ break;
+ }
+
/* always i2c write*/
obuf[0] = 0x08;
obuf[1] = msg[0].addr;
@@ -733,6 +774,19 @@ static int su3000_i2c_transfer(struct i2
break;
case 2:
/* always i2c read */
+ if (4 + msg[0].len > sizeof(obuf)) {
+ warn("i2c rd: len=%d is too big!\n",
+ msg[0].len);
+ num = -EOPNOTSUPP;
+ break;
+ }
+ if (1 + msg[1].len > sizeof(obuf)) {
+ warn("i2c rd: len=%d is too big!\n",
+ msg[1].len);
+ num = -EOPNOTSUPP;
+ break;
+ }
+
obuf[0] = 0x09;
obuf[1] = msg[0].len;
obuf[2] = msg[1].len;
[toc] | [prev] | [next] | [standalone]
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2017-08-18 16:30 +0200 |
| Subject | [PATCH 3.2 24/59] PCI: Fix pci_mmap_fits() for HAVE_PCI_RESOURCE_TO_USER platforms |
| Message-ID | <ufQrF-4YI-33@gated-at.bofh.it> |
| In reply to | #1715183 |
3.2.92-rc1 review patch. If anyone has any objections, please let me know.
------------------
From: David Woodhouse <dwmw@amazon.co.uk>
commit 6bccc7f426abd640f08d8c75fb22f99483f201b4 upstream.
In the PCI_MMAP_PROCFS case when the address being passed by the user is a
'user visible' resource address based on the bus window, and not the actual
contents of the resource, that's what we need to be checking it against.
Signed-off-by: David Woodhouse <dwmw@amazon.co.uk>
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
[bwh: Backported to 3.2: adjust context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
drivers/pci/pci-sysfs.c | 10 +++++++---
1 file changed, 7 insertions(+), 3 deletions(-)
--- a/drivers/pci/pci-sysfs.c
+++ b/drivers/pci/pci-sysfs.c
@@ -772,15 +772,19 @@ void pci_remove_legacy_files(struct pci_
int pci_mmap_fits(struct pci_dev *pdev, int resno, struct vm_area_struct *vma,
enum pci_mmap_api mmap_api)
{
- unsigned long nr, start, size, pci_start;
+ unsigned long nr, start, size;
+ resource_size_t pci_start = 0, pci_end;
if (pci_resource_len(pdev, resno) == 0)
return 0;
nr = (vma->vm_end - vma->vm_start) >> PAGE_SHIFT;
start = vma->vm_pgoff;
size = ((pci_resource_len(pdev, resno) - 1) >> PAGE_SHIFT) + 1;
- pci_start = (mmap_api == PCI_MMAP_PROCFS) ?
- pci_resource_start(pdev, resno) >> PAGE_SHIFT : 0;
+ if (mmap_api == PCI_MMAP_PROCFS) {
+ pci_resource_to_user(pdev, resno, &pdev->resource[resno],
+ &pci_start, &pci_end);
+ pci_start >>= PAGE_SHIFT;
+ }
if (start >= pci_start && start < pci_start + size &&
start + nr <= pci_start + size)
return 1;
[toc] | [prev] | [next] | [standalone]
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2017-08-18 16:30 +0200 |
| Subject | [PATCH 3.2 17/59] [media] gspca: konica: add missing endpoint sanity check |
| Message-ID | <ufQrG-4YI-43@gated-at.bofh.it> |
| In reply to | #1715183 |
3.2.92-rc1 review patch. If anyone has any objections, please let me know.
------------------
From: Johan Hovold <johan@kernel.org>
commit aa58fedb8c7b6cf2f05941d238495f9e2f29655c upstream.
Make sure to check the number of endpoints to avoid accessing memory
beyond the endpoint array should a device lack the expected endpoints.
Note that, as far as I can tell, the gspca framework has already made
sure there is at least one endpoint in the current alternate setting so
there should be no risk for a NULL-pointer dereference here.
Fixes: b517af722860 ("V4L/DVB: gspca_konica: New gspca subdriver for
konica chipset using cams")
Cc: Hans de Goede <hdegoede@redhat.com>
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Hans Verkuil <hansverk@cisco.com>
Signed-off-by: Mauro Carvalho Chehab <mchehab@s-opensource.com>
[bwh: Backported to 3.2: adjust filename]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
drivers/media/video/gspca/konica.c | 3 +++
1 file changed, 3 insertions(+)
--- a/drivers/media/video/gspca/konica.c
+++ b/drivers/media/video/gspca/konica.c
@@ -290,6 +290,9 @@ static int sd_start(struct gspca_dev *gs
return -EIO;
}
+ if (alt->desc.bNumEndpoints < 2)
+ return -ENODEV;
+
packet_size = le16_to_cpu(alt->endpoint[0].desc.wMaxPacketSize);
reg_w(gspca_dev, sd->brightness, BRIGHTNESS_REG);
[toc] | [prev] | [next] | [standalone]
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2017-08-18 16:30 +0200 |
| Subject | [PATCH 3.2 13/59] [media] mceusb: fix NULL-deref at probe |
| Message-ID | <ufQrG-4YI-45@gated-at.bofh.it> |
| In reply to | #1715183 |
3.2.92-rc1 review patch. If anyone has any objections, please let me know.
------------------
From: Johan Hovold <johan@kernel.org>
commit 03eb2a557ed552e920a0942b774aaf931596eec1 upstream.
Make sure to check for the required out endpoint to avoid dereferencing
a NULL-pointer in mce_request_packet should a malicious device lack such
an endpoint. Note that this path is hit during probe.
Fixes: 66e89522aff7 ("V4L/DVB: IR: add mceusb IR receiver driver")
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Sean Young <sean@mess.org>
Signed-off-by: Mauro Carvalho Chehab <mchehab@s-opensource.com>
[bwh: Backported to 3.2: using mce_dbg() instead of dev_dbg()]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
drivers/media/rc/mceusb.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
--- a/drivers/media/rc/mceusb.c
+++ b/drivers/media/rc/mceusb.c
@@ -1301,8 +1301,8 @@ static int __devinit mceusb_dev_probe(st
"found\n");
}
}
- if (ep_in == NULL) {
- mce_dbg(&intf->dev, "inbound and/or endpoint not found\n");
+ if (!ep_in || !ep_out) {
+ mce_dbg(&intf->dev, "required endpoints not found\n");
return -ENODEV;
}
[toc] | [prev] | [next] | [standalone]
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2017-08-18 16:30 +0200 |
| Subject | [PATCH 3.2 20/59] [media] cx231xx-cards: fix NULL-deref at probe |
| Message-ID | <ufQrG-4YI-47@gated-at.bofh.it> |
| In reply to | #1715183 |
3.2.92-rc1 review patch. If anyone has any objections, please let me know.
------------------
From: Johan Hovold <johan@kernel.org>
commit 0cd273bb5e4d1828efaaa8dfd11b7928131ed149 upstream.
Make sure to check the number of endpoints to avoid dereferencing a
NULL-pointer or accessing memory beyond the endpoint array should a
malicious device lack the expected endpoints.
Fixes: e0d3bafd0258 ("V4L/DVB (10954): Add cx231xx USB driver")
Cc: Sri Deevi <Srinivasa.Deevi@conexant.com>
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Hans Verkuil <hans.verkuil@cisco.com>
Signed-off-by: Mauro Carvalho Chehab <mchehab@s-opensource.com>
[bwh: Backported to 3.2: adjust filename, context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
drivers/media/video/cx231xx/cx231xx-cards.c | 45 +++++++++++++++++++++++++++----
1 file changed, 40 insertions(+), 5 deletions(-)
--- a/drivers/media/video/cx231xx/cx231xx-cards.c
+++ b/drivers/media/video/cx231xx/cx231xx-cards.c
@@ -1159,6 +1159,9 @@ static int cx231xx_usb_probe(struct usb_
uif = udev->actconfig->interface[dev->current_pcb_config.
hs_config_info[0].interface_info.video_index + 1];
+ if (uif->altsetting[0].desc.bNumEndpoints < isoc_pipe + 1)
+ return -ENODEV;
+
dev->video_mode.end_point_addr = le16_to_cpu(uif->altsetting[0].
endpoint[isoc_pipe].desc.bEndpointAddress);
@@ -1176,8 +1179,12 @@ static int cx231xx_usb_probe(struct usb_
}
for (i = 0; i < dev->video_mode.num_alt; i++) {
- u16 tmp = le16_to_cpu(uif->altsetting[i].endpoint[isoc_pipe].
- desc.wMaxPacketSize);
+ u16 tmp;
+
+ if (uif->altsetting[i].desc.bNumEndpoints < isoc_pipe + 1)
+ return -ENODEV;
+
+ tmp = le16_to_cpu(uif->altsetting[i].endpoint[isoc_pipe].desc.wMaxPacketSize);
dev->video_mode.alt_max_pkt_size[i] =
(tmp & 0x07ff) * (((tmp & 0x1800) >> 11) + 1);
cx231xx_info("Alternate setting %i, max size= %i\n", i,
@@ -1189,6 +1196,9 @@ static int cx231xx_usb_probe(struct usb_
hs_config_info[0].interface_info.
vanc_index + 1];
+ if (uif->altsetting[0].desc.bNumEndpoints < isoc_pipe + 1)
+ return -ENODEV;
+
dev->vbi_mode.end_point_addr =
le16_to_cpu(uif->altsetting[0].endpoint[isoc_pipe].desc.
bEndpointAddress);
@@ -1207,8 +1217,12 @@ static int cx231xx_usb_probe(struct usb_
}
for (i = 0; i < dev->vbi_mode.num_alt; i++) {
- u16 tmp =
- le16_to_cpu(uif->altsetting[i].endpoint[isoc_pipe].
+ u16 tmp;
+
+ if (uif->altsetting[i].desc.bNumEndpoints < isoc_pipe + 1)
+ return -ENODEV;
+
+ tmp = le16_to_cpu(uif->altsetting[i].endpoint[isoc_pipe].
desc.wMaxPacketSize);
dev->vbi_mode.alt_max_pkt_size[i] =
(tmp & 0x07ff) * (((tmp & 0x1800) >> 11) + 1);
@@ -1221,6 +1235,9 @@ static int cx231xx_usb_probe(struct usb_
hs_config_info[0].interface_info.
hanc_index + 1];
+ if (uif->altsetting[0].desc.bNumEndpoints < isoc_pipe + 1)
+ return -ENODEV;
+
dev->sliced_cc_mode.end_point_addr =
le16_to_cpu(uif->altsetting[0].endpoint[isoc_pipe].desc.
bEndpointAddress);
@@ -1239,7 +1256,12 @@ static int cx231xx_usb_probe(struct usb_
}
for (i = 0; i < dev->sliced_cc_mode.num_alt; i++) {
- u16 tmp = le16_to_cpu(uif->altsetting[i].endpoint[isoc_pipe].
+ u16 tmp;
+
+ if (uif->altsetting[i].desc.bNumEndpoints < isoc_pipe + 1)
+ return -ENODEV;
+
+ tmp = le16_to_cpu(uif->altsetting[i].endpoint[isoc_pipe].
desc.wMaxPacketSize);
dev->sliced_cc_mode.alt_max_pkt_size[i] =
(tmp & 0x07ff) * (((tmp & 0x1800) >> 11) + 1);
@@ -1254,6 +1276,11 @@ static int cx231xx_usb_probe(struct usb_
interface_info.
ts1_index + 1];
+ if (uif->altsetting[0].desc.bNumEndpoints < isoc_pipe + 1) {
+ retval = -ENODEV;
+ goto err_video_alt;
+ }
+
dev->ts1_mode.end_point_addr =
le16_to_cpu(uif->altsetting[0].endpoint[isoc_pipe].
desc.bEndpointAddress);
@@ -1272,7 +1299,14 @@ static int cx231xx_usb_probe(struct usb_
}
for (i = 0; i < dev->ts1_mode.num_alt; i++) {
- u16 tmp = le16_to_cpu(uif->altsetting[i].
+ u16 tmp;
+
+ if (uif->altsetting[i].desc.bNumEndpoints < isoc_pipe + 1) {
+ retval = -ENODEV;
+ goto err_video_alt;
+ }
+
+ tmp = le16_to_cpu(uif->altsetting[i].
endpoint[isoc_pipe].desc.
wMaxPacketSize);
dev->ts1_mode.alt_max_pkt_size[i] =
[toc] | [prev] | [next] | [standalone]
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2017-08-18 16:30 +0200 |
| Subject | [PATCH 3.2 32/59] [media] ttusb2: limit messages to buffer size |
| Message-ID | <ufQrG-4YI-51@gated-at.bofh.it> |
| In reply to | #1715183 |
3.2.92-rc1 review patch. If anyone has any objections, please let me know.
------------------
From: Alyssa Milburn <amilburn@zall.org>
commit a12b8ab8c5ff7ccd7b107a564743507c850a441d upstream.
Otherwise ttusb2_i2c_xfer can read or write beyond the end of static and
heap buffers.
Signed-off-by: Alyssa Milburn <amilburn@zall.org>
Signed-off-by: Mauro Carvalho Chehab <mchehab@s-opensource.com>
[bwh: Backported to 3.2: adjust filename]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
drivers/media/dvb/dvb-usb/ttusb2.c | 19 +++++++++++++++++++
1 file changed, 19 insertions(+)
--- a/drivers/media/dvb/dvb-usb/ttusb2.c
+++ b/drivers/media/dvb/dvb-usb/ttusb2.c
@@ -78,6 +78,9 @@ static int ttusb2_msg(struct dvb_usb_dev
u8 *s, *r = NULL;
int ret = 0;
+ if (4 + rlen > 64)
+ return -EIO;
+
s = kzalloc(wlen+4, GFP_KERNEL);
if (!s)
return -ENOMEM;
@@ -381,6 +384,22 @@ static int ttusb2_i2c_xfer(struct i2c_ad
write_read = i+1 < num && (msg[i+1].flags & I2C_M_RD);
read = msg[i].flags & I2C_M_RD;
+ if (3 + msg[i].len > sizeof(obuf)) {
+ err("i2c wr len=%d too high", msg[i].len);
+ break;
+ }
+ if (write_read) {
+ if (3 + msg[i+1].len > sizeof(ibuf)) {
+ err("i2c rd len=%d too high", msg[i+1].len);
+ break;
+ }
+ } else if (read) {
+ if (3 + msg[i].len > sizeof(ibuf)) {
+ err("i2c rd len=%d too high", msg[i].len);
+ break;
+ }
+ }
+
obuf[0] = (msg[i].addr << 1) | (write_read | read);
if (read)
obuf[1] = 0;
[toc] | [prev] | [next] | [standalone]
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2017-08-18 16:30 +0200 |
| Subject | [PATCH 3.2 02/59] [media] pvrusb2: reduce stack usage pvr2_eeprom_analyze() |
| Message-ID | <ufQrG-4YI-53@gated-at.bofh.it> |
| In reply to | #1715183 |
3.2.92-rc1 review patch. If anyone has any objections, please let me know.
------------------
From: Arnd Bergmann <arnd@arndb.de>
commit 6830733d53a4517588e56227b9c8538633f0c496 upstream.
The driver uses a relatively large data structure on the stack, which
showed up on my radar as we get a warning with the "latent entropy"
GCC plugin:
drivers/media/usb/pvrusb2/pvrusb2-eeprom.c:153:1: error: the frame size of 1376 bytes is larger than 1152 bytes [-Werror=frame-larger-than=]
The warning is usually hidden as we raise the warning limit to 2048
when the plugin is enabled, but I'd like to lower that again in the
future, and making this function smaller helps to do that without
build regressions.
Further analysis shows that putting an 'i2c_client' structure on
the stack is not really supported, as the embedded 'struct device'
is not initialized here, and we are only saved by the fact that
the function that is called here does not use the pointer at all.
Fixes: d855497edbfb ("V4L/DVB (4228a): pvrusb2 to kernel 2.6.18")
Signed-off-by: Arnd Bergmann <arnd@arndb.de>
Signed-off-by: Hans Verkuil <hans.verkuil@cisco.com>
Signed-off-by: Mauro Carvalho Chehab <mchehab@s-opensource.com>
[bwh: Backported to 3.2: adjust filename]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
drivers/media/video/pvrusb2/pvrusb2-eeprom.c | 13 ++++---------
1 file changed, 4 insertions(+), 9 deletions(-)
--- a/drivers/media/video/pvrusb2/pvrusb2-eeprom.c
+++ b/drivers/media/video/pvrusb2/pvrusb2-eeprom.c
@@ -123,15 +123,10 @@ int pvr2_eeprom_analyze(struct pvr2_hdw
memset(&tvdata,0,sizeof(tvdata));
eeprom = pvr2_eeprom_fetch(hdw);
- if (!eeprom) return -EINVAL;
+ if (!eeprom)
+ return -EINVAL;
- {
- struct i2c_client fake_client;
- /* Newer version expects a useless client interface */
- fake_client.addr = hdw->eeprom_addr;
- fake_client.adapter = &hdw->i2c_adap;
- tveeprom_hauppauge_analog(&fake_client,&tvdata,eeprom);
- }
+ tveeprom_hauppauge_analog(NULL, &tvdata, eeprom);
trace_eeprom("eeprom assumed v4l tveeprom module");
trace_eeprom("eeprom direct call results:");
[toc] | [prev] | [next] | [standalone]
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2017-08-18 16:30 +0200 |
| Subject | [PATCH 3.2 22/59] [media] cx231xx-audio: fix NULL-deref at probe |
| Message-ID | <ufQrG-4YI-55@gated-at.bofh.it> |
| In reply to | #1715183 |
3.2.92-rc1 review patch. If anyone has any objections, please let me know.
------------------
From: Johan Hovold <johan@kernel.org>
commit 65f921647f4c89a2068478c89691f39b309b58f7 upstream.
Make sure to check the number of endpoints to avoid dereferencing a
NULL-pointer or accessing memory beyond the endpoint array should a
malicious device lack the expected endpoints.
Fixes: e0d3bafd0258 ("V4L/DVB (10954): Add cx231xx USB driver")
Cc: Sri Deevi <Srinivasa.Deevi@conexant.com>
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Hans Verkuil <hans.verkuil@cisco.com>
Signed-off-by: Mauro Carvalho Chehab <mchehab@s-opensource.com>
[bwh: Backported to 3.2: adjust filename]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
drivers/media/video/cx231xx/cx231xx-audio.c | 17 +++++++++++++++--
1 file changed, 15 insertions(+), 2 deletions(-)
--- a/drivers/media/video/cx231xx/cx231xx-audio.c
+++ b/drivers/media/video/cx231xx/cx231xx-audio.c
@@ -680,6 +680,11 @@ static int cx231xx_audio_init(struct cx2
hs_config_info[0].interface_info.
audio_index + 1];
+ if (uif->altsetting[0].desc.bNumEndpoints < isoc_pipe + 1) {
+ err = -ENODEV;
+ goto err_free_card;
+ }
+
adev->end_point_addr =
le16_to_cpu(uif->altsetting[0].endpoint[isoc_pipe].desc.
bEndpointAddress);
@@ -695,8 +700,14 @@ static int cx231xx_audio_init(struct cx2
}
for (i = 0; i < adev->num_alt; i++) {
- u16 tmp =
- le16_to_cpu(uif->altsetting[i].endpoint[isoc_pipe].desc.
+ u16 tmp;
+
+ if (uif->altsetting[i].desc.bNumEndpoints < isoc_pipe + 1) {
+ err = -ENODEV;
+ goto err_free_pkt_size;
+ }
+
+ tmp = le16_to_cpu(uif->altsetting[i].endpoint[isoc_pipe].desc.
wMaxPacketSize);
adev->alt_max_pkt_size[i] =
(tmp & 0x07ff) * (((tmp & 0x1800) >> 11) + 1);
@@ -706,6 +717,8 @@ static int cx231xx_audio_init(struct cx2
return 0;
+err_free_pkt_size:
+ kfree(adev->alt_max_pkt_size);
err_free_card:
snd_card_free(card);
[toc] | [prev] | [next] | [standalone]
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2017-08-18 16:30 +0200 |
| Subject | [PATCH 3.2 04/59] ath9k_htc: Add PID/VID for a Ubiquiti WiFiStation |
| Message-ID | <ufQrG-4YI-59@gated-at.bofh.it> |
| In reply to | #1715183 |
3.2.92-rc1 review patch. If anyone has any objections, please let me know.
------------------
From: Mohammed Shafi Shajakhan <mohammed@qca.qualcomm.com>
commit 763cbac07674a648f1377b21ca66f577c103fa9a upstream.
Roger says, Ubiquiti produce 2 versions of their WiFiStation USB adapter. One
has an internal antenna, the other has an external antenna and
name suffix EXT. They have separate USB ids and in distribution
openSUSE 12.2 (kernel 3.4.6), file /usr/share/usb.ids shows:
0cf3 Atheros Communications, Inc.
...
b002 Ubiquiti WiFiStation 802.11n [Atheros AR9271]
b003 Ubiquiti WiFiStationEXT 802.11n [Atheros AR9271]
Add b002 Ubiquiti WiFiStation in the PID/VID list.
Reported-by: Roger Price <ath9k@rogerprice.org>
Signed-off-by: Mohammed Shafi Shajakhan <mohammed@qca.qualcomm.com>
Signed-off-by: John W. Linville <linville@tuxdriver.com>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
drivers/net/wireless/ath/ath9k/hif_usb.c | 1 +
1 file changed, 1 insertion(+)
--- a/drivers/net/wireless/ath/ath9k/hif_usb.c
+++ b/drivers/net/wireless/ath/ath9k/hif_usb.c
@@ -38,6 +38,7 @@ static struct usb_device_id ath9k_hif_us
{ USB_DEVICE(0x04CA, 0x4605) }, /* Liteon */
{ USB_DEVICE(0x040D, 0x3801) }, /* VIA */
{ USB_DEVICE(0x0cf3, 0xb003) }, /* Ubiquiti WifiStation Ext */
+ { USB_DEVICE(0x0cf3, 0xb002) }, /* Ubiquiti WifiStation */
{ USB_DEVICE(0x057c, 0x8403) }, /* AVM FRITZ!WLAN 11N v2 USB */
{ USB_DEVICE(0x0cf3, 0x7015),
[toc] | [prev] | [next] | [standalone]
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2017-08-18 16:30 +0200 |
| Subject | [PATCH 3.2 10/59] zd1211rw: fix NULL-deref at probe |
| Message-ID | <ufQrG-4YI-63@gated-at.bofh.it> |
| In reply to | #1715183 |
3.2.92-rc1 review patch. If anyone has any objections, please let me know.
------------------
From: Johan Hovold <johan@kernel.org>
commit ca260ece6a57dc7d751e0685f51fa2c55d851873 upstream.
Make sure to check the number of endpoints to avoid dereferencing a
NULL-pointer or accessing memory beyond the endpoint array should a
malicious device lack the expected endpoints.
Fixes: a1030e92c150 ("[PATCH] zd1211rw: Convert installer CDROM device into WLAN device")
Cc: Daniel Drake <dsd@gentoo.org>
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Kalle Valo <kvalo@codeaurora.org>
[bwh: Backported to 3.2: adjust filename]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
drivers/net/wireless/zd1211rw/zd_usb.c | 3 +++
1 file changed, 3 insertions(+)
--- a/drivers/net/wireless/zd1211rw/zd_usb.c
+++ b/drivers/net/wireless/zd1211rw/zd_usb.c
@@ -1281,6 +1281,9 @@ static int eject_installer(struct usb_in
u8 bulk_out_ep;
int r;
+ if (iface_desc->desc.bNumEndpoints < 2)
+ return -ENODEV;
+
/* Find bulk out endpoint */
for (r = 1; r >= 0; r--) {
endpoint = &iface_desc->endpoint[r].desc;
[toc] | [prev] | [next] | [standalone]
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2017-08-18 16:30 +0200 |
| Subject | [PATCH 3.2 27/59] PCI: Ignore write combining when mapping I/O port space |
| Message-ID | <ufQrG-4YI-61@gated-at.bofh.it> |
| In reply to | #1715183 |
3.2.92-rc1 review patch. If anyone has any objections, please let me know.
------------------
From: Bjorn Helgaas <bhelgaas@google.com>
commit 3a92c319c44a7bcee9f48dff9d97d001943b54c6 upstream.
PCI exposes files like /proc/bus/pci/00/00.0 in procfs. These files
support operations like this:
ioctl(fd, PCIIOC_MMAP_IS_IO); # request I/O port space
ioctl(fd, PCIIOC_WRITE_COMBINE, 1); # request write-combining
mmap(fd, ...)
Write combining is useful on PCI memory space, but I don't think it makes
sense on PCI I/O port space.
We *could* change proc_bus_pci_ioctl() to make it impossible to set
mmap_state == pci_mmap_io and write_combine at the same time, but that
would break the following sequence, which is currently legal:
mmap(fd, ...) # default is I/O, non-combining
ioctl(fd, PCIIOC_WRITE_COMBINE, 1); # request write-combining
ioctl(fd, PCIIOC_MMAP_IS_MEM); # request memory space
mmap(fd, ...) # get write-combining mapping
Ignore the write-combining flag when mapping I/O port space.
This patch should have no functional effect, based on this analysis of all
implementations of pci_mmap_page_range():
- ia64 mips parisc sh unicore32 x86 do not support mapping of I/O port
space at all.
- arm cris microblaze mn10300 sparc xtensa support mapping of I/O port
space, but ignore the write_combine argument to pci_mmap_page_range().
- powerpc supports mapping of I/O port space and uses write_combine, and
it disables write combining for I/O port space in
__pci_mmap_set_pgprot().
This patch makes it possible to remove __pci_mmap_set_pgprot() from
powerpc, which simplifies that path.
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
drivers/pci/proc.c | 9 ++++++---
1 file changed, 6 insertions(+), 3 deletions(-)
--- a/drivers/pci/proc.c
+++ b/drivers/pci/proc.c
@@ -249,7 +249,7 @@ static int proc_bus_pci_mmap(struct file
const struct proc_dir_entry *dp = PDE(inode);
struct pci_dev *dev = dp->data;
struct pci_filp_private *fpriv = file->private_data;
- int i, ret;
+ int i, ret, write_combine;
if (!capable(CAP_SYS_RAWIO))
return -EPERM;
@@ -263,9 +263,12 @@ static int proc_bus_pci_mmap(struct file
if (i >= PCI_ROM_RESOURCE)
return -ENODEV;
+ if (fpriv->mmap_state == pci_mmap_mem)
+ write_combine = fpriv->write_combine;
+ else
+ write_combine = 0;
ret = pci_mmap_page_range(dev, vma,
- fpriv->mmap_state,
- fpriv->write_combine);
+ fpriv->mmap_state, write_combine);
if (ret < 0)
return ret;
[toc] | [prev] | [next] | [standalone]
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2017-08-18 16:30 +0200 |
| Subject | [PATCH 3.2 06/59] ath9k_htc: Add new USB ID |
| Message-ID | <ufQrH-4YI-71@gated-at.bofh.it> |
| In reply to | #1715183 |
3.2.92-rc1 review patch. If anyone has any objections, please let me know.
------------------
From: Leon Nardella <leon.nardella@gmail.com>
commit 0088d27b78f2c0118aee82923269518616481ea0 upstream.
This device is a dongle made by Philips to enhance their TVs with wireless capabilities,
but works flawlessly on any upstream kernel, provided that the ath9k_htc module is attached to it.
It's correctly recognized by lsusb as "0471:209e Philips (or NXP) PTA01 Wireless Adapter" and the
patch has been tested on real hardware.
Signed-off-by: Leon Nardella <leon.nardella@gmail.com>
Signed-off-by: Kalle Valo <kvalo@codeaurora.org>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
drivers/net/wireless/ath/ath9k/hif_usb.c | 1 +
1 file changed, 1 insertion(+)
--- a/drivers/net/wireless/ath/ath9k/hif_usb.c
+++ b/drivers/net/wireless/ath/ath9k/hif_usb.c
@@ -40,6 +40,7 @@ static struct usb_device_id ath9k_hif_us
{ USB_DEVICE(0x0cf3, 0xb003) }, /* Ubiquiti WifiStation Ext */
{ USB_DEVICE(0x0cf3, 0xb002) }, /* Ubiquiti WifiStation */
{ USB_DEVICE(0x057c, 0x8403) }, /* AVM FRITZ!WLAN 11N v2 USB */
+ { USB_DEVICE(0x0471, 0x209e) }, /* Philips (or NXP) PTA01 */
{ USB_DEVICE(0x0cf3, 0x7015),
.driver_info = AR9287_USB }, /* Atheros */
[toc] | [prev] | [next] | [standalone]
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2017-08-18 16:30 +0200 |
| Subject | [PATCH 3.2 25/59] [media] digitv: limit messages to buffer size |
| Message-ID | <ufQrH-4YI-75@gated-at.bofh.it> |
| In reply to | #1715183 |
3.2.92-rc1 review patch. If anyone has any objections, please let me know.
------------------
From: Alyssa Milburn <amilburn@zall.org>
commit 821117dc21083a99dd99174c10848d70ff43de29 upstream.
Return an error rather than memcpy()ing beyond the end of the buffer.
Internal callers use appropriate sizes, but digitv_i2c_xfer may not.
Signed-off-by: Alyssa Milburn <amilburn@zall.org>
Signed-off-by: Mauro Carvalho Chehab <mchehab@s-opensource.com>
[bwh: Backported to 3.2: adjust filename, context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
--- a/drivers/media/dvb/dvb-usb/digitv.c
+++ b/drivers/media/dvb/dvb-usb/digitv.c
@@ -30,6 +30,10 @@ static int digitv_ctrl_msg(struct dvb_us
{
int wo = (rbuf == NULL || rlen == 0); /* write-only */
u8 sndbuf[7],rcvbuf[7];
+
+ if (wlen > 4 || rlen > 4)
+ return -EIO;
+
memset(sndbuf,0,7); memset(rcvbuf,0,7);
sndbuf[0] = cmd;
[toc] | [prev] | [next] | [standalone]
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2017-08-18 16:30 +0200 |
| Subject | [PATCH 3.2 18/59] [media] usbvision: fix NULL-deref at probe |
| Message-ID | <ufQrH-4YI-73@gated-at.bofh.it> |
| In reply to | #1715183 |
3.2.92-rc1 review patch. If anyone has any objections, please let me know.
------------------
From: Johan Hovold <johan@kernel.org>
commit eacb975b48272f54532b62f515a3cf7eefa35123 upstream.
Make sure to check the number of endpoints to avoid dereferencing a
NULL-pointer or accessing memory beyond the endpoint array should a
malicious device lack the expected endpoints.
Fixes: 2a9f8b5d25be ("V4L/DVB (5206): Usbvision: set alternate interface
modification")
Cc: Thierry MERLE <thierry.merle@free.fr>
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Hans Verkuil <hans.verkuil@cisco.com>
Signed-off-by: Mauro Carvalho Chehab <mchehab@s-opensource.com>
[bwh: Backported to 3.2: adjust filename]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
drivers/media/video/usbvision/usbvision-video.c | 9 ++++++++-
1 file changed, 8 insertions(+), 1 deletion(-)
--- a/drivers/media/video/usbvision/usbvision-video.c
+++ b/drivers/media/video/usbvision/usbvision-video.c
@@ -1564,7 +1564,14 @@ static int __devinit usbvision_probe(str
}
for (i = 0; i < usbvision->num_alt; i++) {
- u16 tmp = le16_to_cpu(uif->altsetting[i].endpoint[1].desc.
+ u16 tmp;
+
+ if (uif->altsetting[i].desc.bNumEndpoints < 2) {
+ ret = -ENODEV;
+ goto err_pkt;
+ }
+
+ tmp = le16_to_cpu(uif->altsetting[i].endpoint[1].desc.
wMaxPacketSize);
usbvision->alt_max_pkt_size[i] =
(tmp & 0x07ff) * (((tmp & 0x1800) >> 11) + 1);
[toc] | [prev] | [next] | [standalone]
| From | Guenter Roeck <linux@roeck-us.net> |
|---|---|
| Date | 2017-08-18 17:00 +0200 |
| Message-ID | <ufQUF-58U-7@gated-at.bofh.it> |
| In reply to | #1715183 |
On 08/18/2017 06:13 AM, Ben Hutchings wrote: > This is the start of the stable review cycle for the 3.2.92 release. > There are 59 patches in this series, which will be posted as responses > to this one. If anyone has any issues with these being applied, please > let me know. > > Responses should be made by Mon Aug 21 18:00:00 UTC 2017. > Anything received after that time might be too late. > Build results: total: 86 pass: 86 fail: 0 Qemu test results: total: 69 pass: 69 fail: 0 Details are available at http://kerneltests.org/builders. Guenter
[toc] | [prev] | [standalone]
Back to top | Article view | linux.kernel
csiph-web