aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorFuqian Huang <huangfq.daxian@gmail.com>2019-04-18 00:35:57 -0400
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>2019-04-25 05:58:56 -0400
commit29973f8a88b001ebc605c88cdee124f7256ecdbf (patch)
tree8606f14cb8e4a3c6f186d8e049f15266be01c59e
parent8daa89e099708db1ffc694c812cb3c0737f1e22b (diff)
tty: rocket: Remove RCPK_GET_STRUCT ioctl
If the cmd is RCPK_GET_STRUCT, copy_to_user will copy info to user space. As info->port.ops is the address of a constant object rocket_port_ops (assigned in init_r_port), a kernel address leakage happens. Remove the RCPK_GET_STRUCT ioctl. Signed-off-by: Fuqian Huang <huangfq.daxian@gmail.com> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
-rw-r--r--drivers/tty/rocket.c4
-rw-r--r--drivers/tty/rocket.h1
2 files changed, 0 insertions, 5 deletions
diff --git a/drivers/tty/rocket.c b/drivers/tty/rocket.c
index b121d8f8f3d7..b6543e28bd8b 100644
--- a/drivers/tty/rocket.c
+++ b/drivers/tty/rocket.c
@@ -1283,10 +1283,6 @@ static int rp_ioctl(struct tty_struct *tty,
1283 return -ENXIO; 1283 return -ENXIO;
1284 1284
1285 switch (cmd) { 1285 switch (cmd) {
1286 case RCKP_GET_STRUCT:
1287 if (copy_to_user(argp, info, sizeof (struct r_port)))
1288 ret = -EFAULT;
1289 break;
1290 case RCKP_GET_CONFIG: 1286 case RCKP_GET_CONFIG:
1291 ret = get_config(info, argp); 1287 ret = get_config(info, argp);
1292 break; 1288 break;
diff --git a/drivers/tty/rocket.h b/drivers/tty/rocket.h
index d0560203f215..d62ed6587f32 100644
--- a/drivers/tty/rocket.h
+++ b/drivers/tty/rocket.h
@@ -71,7 +71,6 @@ struct rocket_version {
71/* 71/*
72 * Rocketport ioctls -- "RP" 72 * Rocketport ioctls -- "RP"
73 */ 73 */
74#define RCKP_GET_STRUCT 0x00525001
75#define RCKP_GET_CONFIG 0x00525002 74#define RCKP_GET_CONFIG 0x00525002
76#define RCKP_SET_CONFIG 0x00525003 75#define RCKP_SET_CONFIG 0x00525003
77#define RCKP_GET_PORTS 0x00525004 76#define RCKP_GET_PORTS 0x00525004