diff options
| author | Oliver Neukum <oliver@neukum.org> | 2007-10-25 10:05:53 -0400 |
|---|---|---|
| committer | Greg Kroah-Hartman <gregkh@suse.de> | 2007-10-25 15:18:46 -0400 |
| commit | d5d1ceac2a47645780bd07fd7a670b14c4d995db (patch) | |
| tree | 9c2fa21fa6339fb25544bbed82b249b5d62a36c4 | |
| parent | 78663ecc344b4694dd737deb682e81312a0684b6 (diff) | |
USB: open disconnect race in usblcd
this driver has a possible use after free due to a race when disconnect
and open handle intfdata without a lock.
Signed-off-by: Oliver Neukum <oneukum@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
| -rw-r--r-- | drivers/usb/misc/usblcd.c | 11 |
1 files changed, 10 insertions, 1 deletions
diff --git a/drivers/usb/misc/usblcd.c b/drivers/usb/misc/usblcd.c index 719842032712..20777d01db62 100644 --- a/drivers/usb/misc/usblcd.c +++ b/drivers/usb/misc/usblcd.c | |||
| @@ -17,6 +17,7 @@ | |||
| 17 | #include <linux/init.h> | 17 | #include <linux/init.h> |
| 18 | #include <linux/slab.h> | 18 | #include <linux/slab.h> |
| 19 | #include <linux/errno.h> | 19 | #include <linux/errno.h> |
| 20 | #include <linux/mutex.h> | ||
| 20 | #include <asm/uaccess.h> | 21 | #include <asm/uaccess.h> |
| 21 | #include <linux/usb.h> | 22 | #include <linux/usb.h> |
| 22 | 23 | ||
| @@ -34,6 +35,8 @@ static struct usb_device_id id_table [] = { | |||
| 34 | }; | 35 | }; |
| 35 | MODULE_DEVICE_TABLE (usb, id_table); | 36 | MODULE_DEVICE_TABLE (usb, id_table); |
| 36 | 37 | ||
| 38 | static DEFINE_MUTEX(open_disc_mutex); | ||
| 39 | |||
| 37 | 40 | ||
| 38 | struct usb_lcd { | 41 | struct usb_lcd { |
| 39 | struct usb_device * udev; /* init: probe_lcd */ | 42 | struct usb_device * udev; /* init: probe_lcd */ |
| @@ -79,12 +82,16 @@ static int lcd_open(struct inode *inode, struct file *file) | |||
| 79 | return -ENODEV; | 82 | return -ENODEV; |
| 80 | } | 83 | } |
| 81 | 84 | ||
| 85 | mutex_lock(&open_disc_mutex); | ||
| 82 | dev = usb_get_intfdata(interface); | 86 | dev = usb_get_intfdata(interface); |
| 83 | if (!dev) | 87 | if (!dev) { |
| 88 | mutex_unlock(&open_disc_mutex); | ||
| 84 | return -ENODEV; | 89 | return -ENODEV; |
| 90 | } | ||
| 85 | 91 | ||
| 86 | /* increment our usage count for the device */ | 92 | /* increment our usage count for the device */ |
| 87 | kref_get(&dev->kref); | 93 | kref_get(&dev->kref); |
| 94 | mutex_unlock(&open_disc_mutex); | ||
| 88 | 95 | ||
| 89 | /* grab a power reference */ | 96 | /* grab a power reference */ |
| 90 | r = usb_autopm_get_interface(interface); | 97 | r = usb_autopm_get_interface(interface); |
| @@ -393,8 +400,10 @@ static void lcd_disconnect(struct usb_interface *interface) | |||
| 393 | struct usb_lcd *dev; | 400 | struct usb_lcd *dev; |
| 394 | int minor = interface->minor; | 401 | int minor = interface->minor; |
| 395 | 402 | ||
| 403 | mutex_lock(&open_disc_mutex); | ||
| 396 | dev = usb_get_intfdata(interface); | 404 | dev = usb_get_intfdata(interface); |
| 397 | usb_set_intfdata(interface, NULL); | 405 | usb_set_intfdata(interface, NULL); |
| 406 | mutex_unlock(&open_disc_mutex); | ||
| 398 | 407 | ||
| 399 | /* give back our minor */ | 408 | /* give back our minor */ |
| 400 | usb_deregister_dev(interface, &lcd_class); | 409 | usb_deregister_dev(interface, &lcd_class); |
