From cd8dbdaeb57c9b8173cbb33aa46694c751c515c2 Mon Sep 17 00:00:00 2001 From: Chandana Kishori Chiluveru Date: Mon, 10 Sep 2018 19:27:36 +0530 Subject: [PATCH] usb: gadget: Avoid NULL pointer dereference during OS descriptors handling With multi-config compositions some hosts can bind the configuration incorrectly and sending os descriptor request on invalid interface. This could cause accessing NULL pointer and results in panic. Fix this by bailing out from the OS descriptor setup request handling if the interface is NULL. Change-Id: I65f01b876a46b907eb883e48878fc081860b0753 Signed-off-by: Chandana Kishori Chiluveru --- drivers/usb/gadget/composite.c | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/drivers/usb/gadget/composite.c b/drivers/usb/gadget/composite.c index bb47d39aa0ff..f03afbc6692a 100644 --- a/drivers/usb/gadget/composite.c +++ b/drivers/usb/gadget/composite.c @@ -1577,6 +1577,9 @@ static int count_ext_prop(struct usb_configuration *c, int interface) struct usb_function *f; int j; + if (interface >= c->next_interface_id) + return -EINVAL; + f = c->interface[interface]; for (j = 0; j < f->os_desc_n; ++j) { struct usb_os_desc *d; @@ -1596,6 +1599,9 @@ static int len_ext_prop(struct usb_configuration *c, int interface) struct usb_os_desc *d; int j, res; + if (interface >= c->next_interface_id) + return -EINVAL; + res = 10; /* header length */ f = c->interface[interface]; for (j = 0; j < f->os_desc_n; ++j) { @@ -1976,6 +1982,8 @@ unknown: buf[6] = w_index; count = count_ext_prop(os_desc_cfg, interface); + if (count < 0) + return count; put_unaligned_le16(count, buf + 8); count = len_ext_prop(os_desc_cfg, interface);