[ Upstream commit d293ca716e7d5dffdaecaf6b9b2f857a33dc3d3a ]
tipc_msg_validate() can potentially reallocate the skb it is validating,
freeing the old one. In tipc_buf_append(), it was being called with a
pointer to a local variable which was a copy of the caller's skb
pointer.
If the skb was reallocated and validation subsequently failed, the error
handling path would free the original skb pointer, which had already
been freed, leading to double-free.
Fix this by checking if head now points to a newly allocated reassembled
skb. If it does, reassign *headbuf for later freeing operations.
Bug: 500022799
Fixes: d618d09a68 ("tipc: enforce valid ratio between skb truesize and contents")
Suggested-by: Tung Nguyen <tung.quang.nguyen@est.tech>
Signed-off-by: Lee Jones <lee@kernel.org>
Reviewed-by: Tung Nguyen <tung.quang.nguyen@est.tech>
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
[uli: backport to 4.19]
Signed-off-by: Ulrich Hecht <uli@kernel.org>
Reviewed-by: Pavel Machek <pavel@nabladev.com>
Reviewed-by: Nobuhiro Iwamatsu <nobuhiro.iwamatsu.x90@mail.toshiba>
Change-Id: I76d957597768652e2f05be3470bf960f6ff29085
Presently, if the force feedback initialisation fails when probing the
Logitech G920 Driving Force Racing Wheel for Xbox One, an error number
will be returned and propagated before the userspace infrastructure
(sysfs and /dev/input) has been torn down. If userspace ignores the
errors and continues to use its references to these dangling entities, a
UAF will promptly follow.
We have 2 options; continue to return the error, but ensure that all of
the infrastructure is torn down accordingly or continue to treat this
condition as a warning by emitting the message but returning success.
It is thought that the original author's intention was to emit the
warning but keep the device functional, less the force feedback feature,
so let's go with that.
Bug: 482992246
Signed-off-by: Lee Jones <lee@kernel.org>
Reviewed-by: Günther Noack <gnoack@google.com>
Signed-off-by: Benjamin Tissoires <bentiss@kernel.org>
(cherry picked from commit f7a4c78bfeb320299c1b641500fe7761eadbd101) # HID
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I2d2148fc1fd977b47e07523ee977070dbfa149b5
In nfc_llcp_recv_hdlc() and nfc_llcp_recv_disc(), when the socket
state is LLCP_CLOSED, the code correctly calls release_sock() and
nfc_llcp_sock_put() but fails to return. Execution falls through to
the remainder of the function, which calls release_sock() and
nfc_llcp_sock_put() again. This results in a double release_sock()
and a refcount underflow via double nfc_llcp_sock_put(), leading to
a use-after-free.
Add the missing return statements after the LLCP_CLOSED branches
in both functions to prevent the fall-through.
Bug: 499350302
Fixes: d646960f79 ("NFC: Initial LLCP support")
Signed-off-by: Junxi Qian <qjx1298677004@gmail.com>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260408081006.3723-1-qjx1298677004@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 2b5dd4632966c39da6ba74dbc8689b309065e82c)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I041f20fc1fea32f715d2646579fab071e58688d8
[ 2.458802] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000010
[ 2.459516] Internal error: Oops: 96000005 [#1] PREEMPT SMP
[ 2.459788] Modules linked in: ec617_drv(+) wcd9xxx_dlkm(+) bolero_cdc_dlkm(+) mbhc_dlkm stub_dlkm q6_dlkm adsp_loader_dlkm leds_aw2016 wcd937x_slave_dlkm rdbg focaltech_fts sec_ts_drv(+) p73 btpower apr_dlkm wcd938x_slave_dlkm wsa881x_analog_dlkm bu520x1nvx q6_notifier_dlkm rmnet_shs wcd_core_dlkm rmnet_offload q6_pdr_dlkm haptic snd_event_dlkm rmnet_core swr_dlkm rmnet_ctl snx0
[ 2.460075] CPU: 2 PID: 546 Comm: modprobe Tainted: G S 5.4.302-qgki-g3972ebf038eb #3
[ 2.460221] Hardware name: Sony Mobile Communications. PDX225(BLAIR v4) (DT)
[ 2.460285] pstate: 80400005 (Nzcv daif +PAN -UAO)
[ 2.460398] pc : __cfi_check_fail+0x4/0x50 [ec617_drv]
[ 2.460457] lr : __cfi_check+0x1ac/0x1e0 [ec617_drv]
[ 2.460912] x21: 02b3a43e29242445 x20: 0000000000000010
[ 2.462187] Call trace:
[ 2.462240] __cfi_check_fail+0x4/0x50 [ec617_drv]
[ 2.462332] __cfi_slowpath+0x10c/0x168
[ 2.462383] do_one_initcall+0x1dc/0x384
[ 2.462435] do_init_module+0x4c/0x204
[ 2.462522] load_module+0x1734/0x18c0
[ 2.462569] __arm64_sys_finit_module+0xb4/0xf0
[ 2.462617] el0_svc_common+0xc0/0x1a8
[ 2.462698] el0_svc_handler+0x24/0x70
[ 2.462745] el0_svc+0x8/0x100
[ 2.462877] ---[ end trace 711a96c503b0de92 ]---
[ 2.481911] Kernel panic - not syncing: Fatal exception
module_init()/module_exit() define init_module/cleanup_module as aliases
of the given functions. With clang r584948 and cross-DSO CFI, such an
alias only gets its own jump table entry when the aliasee has internal
linkage. Since egisfp_init()/egisfp_exit() were declared non-static,
modpost ended up pointing __this_module.init at the raw .init.text
address instead of init_module.cfi_jt:
R_AARCH64_ABS64 init_module + 0
R_AARCH64_ABS64 cleanup_module + 0
__cfi_check() then compared the initcall pointer (type id
02b3a43e29242445) against egisfp_init.cfi_jt, failed, and jumped to
__cfi_check_fail(), which faulted while dereferencing its bogus diag
argument.
Make both functions static, as they should have been in the first place.
The relocations now resolve to the jump table:
R_AARCH64_ABS64 init_module.cfi_jt + 0
R_AARCH64_ABS64 cleanup_module.cfi_jt + 0
Assisted-by: ClaudeCode:claude-opus-5
Change-Id: I3bf5a698bc5103e1fe0ae13e4c9c52cad9b41c7e
This fixes the following warning when building with newer clang:
error: implicit conversion from enumeration type
'A_STATUS' to different enumeration type 'QDF_STATUS' [-Werror,-Wimplicit-enum-enum-cast]
Change-Id: I84f9f9b0406fad6df74749cbcb2cb176d42525aa
Signed-off-by: angelomds42 <angelomds42@gmail.com>
2026-08-28 11:13:36 +02:00
8 changed files with 29 additions and 13 deletions