aboutsummaryrefslogtreecommitdiffstats
path: root/drivers/firewire
diff options
context:
space:
mode:
authorStefan Richter <stefanr@s5r6.in-berlin.de>2012-10-06 08:12:56 -0400
committerStefan Richter <stefanr@s5r6.in-berlin.de>2012-10-09 12:26:28 -0400
commit790198f74c9d1b46b6a89504361b1a844670d050 (patch)
treeb5cd7146d2eb17c15940f6b89fae3284bc495ddb /drivers/firewire
parent4d50c44381c981c9caa74e82ab894d4938dac9ca (diff)
firewire: cdev: fix user memory corruption (i386 userland on amd64 kernel)
Fix two bugs of the /dev/fw* character device concerning the FW_CDEV_IOC_GET_INFO ioctl with nonzero fw_cdev_get_info.bus_reset. (Practically all /dev/fw* clients issue this ioctl right after opening the device.) Both bugs are caused by sizeof(struct fw_cdev_event_bus_reset) being 36 without natural alignment and 40 with natural alignment. 1) Memory corruption, affecting i386 userland on amd64 kernel: Userland reserves a 36 bytes large buffer, kernel writes 40 bytes. This has been first found and reported against libraw1394 if compiled with gcc 4.7 which happens to order libraw1394's stack such that the bug became visible as data corruption. 2) Information leak, affecting all kernel architectures except i386: 4 bytes of random kernel stack data were leaked to userspace. Hence limit the respective copy_to_user() to the 32-bit aligned size of struct fw_cdev_event_bus_reset. Reported-by: Simon Kirby <sim@hostway.ca> Signed-off-by: Stefan Richter <stefanr@s5r6.in-berlin.de> Cc: stable@kernel.org
Diffstat (limited to 'drivers/firewire')
-rw-r--r--drivers/firewire/core-cdev.c4
1 files changed, 2 insertions, 2 deletions
diff --git a/drivers/firewire/core-cdev.c b/drivers/firewire/core-cdev.c
index 2783f69dada6..f8d22872d753 100644
--- a/drivers/firewire/core-cdev.c
+++ b/drivers/firewire/core-cdev.c
@@ -473,8 +473,8 @@ static int ioctl_get_info(struct client *client, union ioctl_arg *arg)
473 client->bus_reset_closure = a->bus_reset_closure; 473 client->bus_reset_closure = a->bus_reset_closure;
474 if (a->bus_reset != 0) { 474 if (a->bus_reset != 0) {
475 fill_bus_reset_event(&bus_reset, client); 475 fill_bus_reset_event(&bus_reset, client);
476 ret = copy_to_user(u64_to_uptr(a->bus_reset), 476 /* unaligned size of bus_reset is 36 bytes */
477 &bus_reset, sizeof(bus_reset)); 477 ret = copy_to_user(u64_to_uptr(a->bus_reset), &bus_reset, 36);
478 } 478 }
479 if (ret == 0 && list_empty(&client->link)) 479 if (ret == 0 && list_empty(&client->link))
480 list_add_tail(&client->link, &client->device->client_list); 480 list_add_tail(&client->link, &client->device->client_list);