android_kernel_motorola_sm6375/drivers
Repository files (latest commit first)
Filename Latest commit message Latest commit date
GONG Ruiqi e44532b1c3 vgacon: Add check for vc_origin address range in vgacon_scroll()
commit 864f9963ec6b4b76d104d595ba28110b87158003 upstream.

Our in-house Syzkaller reported the following BUG (twice), which we
believed was the same issue with [1]:

==================================================================
BUG: KASAN: slab-out-of-bounds in vcs_scr_readw+0xc2/0xd0 drivers/tty/vt/vt.c:4740
Read of size 2 at addr ffff88800f5bef60 by task syz.7.2620/12393
...
Call Trace:
 <TASK>
 __dump_stack lib/dump_stack.c:88 [inline]
 dump_stack_lvl+0x72/0xa0 lib/dump_stack.c:106
 print_address_description.constprop.0+0x6b/0x3d0 mm/kasan/report.c:364
 print_report+0xba/0x280 mm/kasan/report.c:475
 kasan_report+0xa9/0xe0 mm/kasan/report.c:588
 vcs_scr_readw+0xc2/0xd0 drivers/tty/vt/vt.c:4740
 vcs_write_buf_noattr drivers/tty/vt/vc_screen.c:493 [inline]
 vcs_write+0x586/0x840 drivers/tty/vt/vc_screen.c:690
 vfs_write+0x219/0x960 fs/read_write.c:584
 ksys_write+0x12e/0x260 fs/read_write.c:639
 do_syscall_x64 arch/x86/entry/common.c:51 [inline]
 do_syscall_64+0x59/0x110 arch/x86/entry/common.c:81
 entry_SYSCALL_64_after_hwframe+0x78/0xe2
 ...
 </TASK>

Allocated by task 5614:
 kasan_save_stack+0x20/0x40 mm/kasan/common.c:45
 kasan_set_track+0x25/0x30 mm/kasan/common.c:52
 ____kasan_kmalloc mm/kasan/common.c:374 [inline]
 __kasan_kmalloc+0x8f/0xa0 mm/kasan/common.c:383
 kasan_kmalloc include/linux/kasan.h:201 [inline]
 __do_kmalloc_node mm/slab_common.c:1007 [inline]
 __kmalloc+0x62/0x140 mm/slab_common.c:1020
 kmalloc include/linux/slab.h:604 [inline]
 kzalloc include/linux/slab.h:721 [inline]
 vc_do_resize+0x235/0xf40 drivers/tty/vt/vt.c:1193
 vgacon_adjust_height+0x2d4/0x350 drivers/video/console/vgacon.c:1007
 vgacon_font_set+0x1f7/0x240 drivers/video/console/vgacon.c:1031
 con_font_set drivers/tty/vt/vt.c:4628 [inline]
 con_font_op+0x4da/0xa20 drivers/tty/vt/vt.c:4675
 vt_k_ioctl+0xa10/0xb30 drivers/tty/vt/vt_ioctl.c:474
 vt_ioctl+0x14c/0x1870 drivers/tty/vt/vt_ioctl.c:752
 tty_ioctl+0x655/0x1510 drivers/tty/tty_io.c:2779
 vfs_ioctl fs/ioctl.c:51 [inline]
 __do_sys_ioctl fs/ioctl.c:871 [inline]
 __se_sys_ioctl+0x12d/0x190 fs/ioctl.c:857
 do_syscall_x64 arch/x86/entry/common.c:51 [inline]
 do_syscall_64+0x59/0x110 arch/x86/entry/common.c:81
 entry_SYSCALL_64_after_hwframe+0x78/0xe2

Last potentially related work creation:
 kasan_save_stack+0x20/0x40 mm/kasan/common.c:45
 __kasan_record_aux_stack+0x94/0xa0 mm/kasan/generic.c:492
 __call_rcu_common.constprop.0+0xc3/0xa10 kernel/rcu/tree.c:2713
 netlink_release+0x620/0xc20 net/netlink/af_netlink.c:802
 __sock_release+0xb5/0x270 net/socket.c:663
 sock_close+0x1e/0x30 net/socket.c:1425
 __fput+0x408/0xab0 fs/file_table.c:384
 __fput_sync+0x4c/0x60 fs/file_table.c:465
 __do_sys_close fs/open.c:1580 [inline]
 __se_sys_close+0x68/0xd0 fs/open.c:1565
 do_syscall_x64 arch/x86/entry/common.c:51 [inline]
 do_syscall_64+0x59/0x110 arch/x86/entry/common.c:81
 entry_SYSCALL_64_after_hwframe+0x78/0xe2

Second to last potentially related work creation:
 kasan_save_stack+0x20/0x40 mm/kasan/common.c:45
 __kasan_record_aux_stack+0x94/0xa0 mm/kasan/generic.c:492
 __call_rcu_common.constprop.0+0xc3/0xa10 kernel/rcu/tree.c:2713
 netlink_release+0x620/0xc20 net/netlink/af_netlink.c:802
 __sock_release+0xb5/0x270 net/socket.c:663
 sock_close+0x1e/0x30 net/socket.c:1425
 __fput+0x408/0xab0 fs/file_table.c:384
 task_work_run+0x154/0x240 kernel/task_work.c:239
 exit_task_work include/linux/task_work.h:45 [inline]
 do_exit+0x8e5/0x1320 kernel/exit.c:874
 do_group_exit+0xcd/0x280 kernel/exit.c:1023
 get_signal+0x1675/0x1850 kernel/signal.c:2905
 arch_do_signal_or_restart+0x80/0x3b0 arch/x86/kernel/signal.c:310
 exit_to_user_mode_loop kernel/entry/common.c:111 [inline]
 exit_to_user_mode_prepare include/linux/entry-common.h:328 [inline]
 __syscall_exit_to_user_mode_work kernel/entry/common.c:207 [inline]
 syscall_exit_to_user_mode+0x1b3/0x1e0 kernel/entry/common.c:218
 do_syscall_64+0x66/0x110 arch/x86/entry/common.c:87
 entry_SYSCALL_64_after_hwframe+0x78/0xe2

The buggy address belongs to the object at ffff88800f5be000
 which belongs to the cache kmalloc-2k of size 2048
The buggy address is located 2656 bytes to the right of
 allocated 1280-byte region [ffff88800f5be000, ffff88800f5be500)

...

Memory state around the buggy address:
 ffff88800f5bee00: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
 ffff88800f5bee80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
>ffff88800f5bef00: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
                                                       ^
 ffff88800f5bef80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
 ffff88800f5bf000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
==================================================================

By analyzing the vmcore, we found that vc->vc_origin was somehow placed
one line prior to vc->vc_screenbuf when vc was in KD_TEXT mode, and
further writings to /dev/vcs caused out-of-bounds reads (and writes
right after) in vcs_write_buf_noattr().

Our further experiments show that in most cases, vc->vc_origin equals to
vga_vram_base when the console is in KD_TEXT mode, and it's around
vc->vc_screenbuf for the KD_GRAPHICS mode. But via triggerring a
TIOCL_SETVESABLANK ioctl beforehand, we can make vc->vc_origin be around
vc->vc_screenbuf while the console is in KD_TEXT mode, and then by
writing the special 'ESC M' control sequence to the tty certain times
(depends on the value of `vc->state.y - vc->vc_top`), we can eventually
move vc->vc_origin prior to vc->vc_screenbuf. Here's the PoC, tested on
QEMU:

```
int main() {
	const int RI_NUM = 10; // should be greater than `vc->state.y - vc->vc_top`
	int tty_fd, vcs_fd;
	const char *tty_path = "/dev/tty0";
	const char *vcs_path = "/dev/vcs";
	const char escape_seq[] = "\x1bM";  // ESC + M
	const char trigger_seq[] = "Let's trigger an OOB write.";
	struct vt_sizes vt_size = { 70, 2 };
	int blank = TIOCL_BLANKSCREEN;

	tty_fd = open(tty_path, O_RDWR);

	char vesa_mode[] = { TIOCL_SETVESABLANK, 1 };
	ioctl(tty_fd, TIOCLINUX, vesa_mode);

	ioctl(tty_fd, TIOCLINUX, &blank);
	ioctl(tty_fd, VT_RESIZE, &vt_size);

	for (int i = 0; i < RI_NUM; ++i)
		write(tty_fd, escape_seq, sizeof(escape_seq) - 1);

	vcs_fd = open(vcs_path, O_RDWR);
	write(vcs_fd, trigger_seq, sizeof(trigger_seq));

	close(vcs_fd);
	close(tty_fd);
	return 0;
}
```

To solve this problem, add an address range validation check in
vgacon_scroll(), ensuring vc->vc_origin never precedes vc_screenbuf.

Reported-by: syzbot+9c09fda97a1a65ea859b@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=9c09fda97a1a65ea859b [1]
Fixes: 1da177e4c3 ("Linux-2.6.12-rc2")
Cc: stable@vger.kernel.org
Co-developed-by: Yi Yang <yiyang13@huawei.com>
Signed-off-by: Yi Yang <yiyang13@huawei.com>
Signed-off-by: GONG Ruiqi <gongruiqi1@huawei.com>
Signed-off-by: Helge Deller <deller@gmx.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-06-27 11:02:51 +01:00
..
accessibility
acpi ACPI: OSI: Stop advertising support for "3.0 _SCP Extensions" 2025-06-27 11:02:45 +01:00
amba
android binder: fix UAF caused by offsets overwrite 2024-09-12 11:03:55 +02:00
ata ata: pata_via: Force PIO for ATAPI devices on VT6415/VT6330 2025-06-27 11:02:51 +01:00
atm
auxdisplay
base pmdomain: core: Fix error checking in genpd_dev_pm_attach_by_id() 2025-06-27 11:02:49 +01:00
bcma
block nbd: don't allow reconnect after disconnect 2025-03-13 12:42:52 +01:00
bluetooth Bluetooth: btrtl: Prevent potential NULL dereference 2025-05-02 07:39:19 +02:00
bus bus: fsl-mc: do not add a device-link for the UAPI used DPMCP device 2025-06-27 11:02:51 +01:00
cdrom
char virtio_console: fix missing byte order handling for cols and rows 2025-05-02 07:39:26 +02:00
clk clk: check for disabled clock-provider in of_clk_get_hw_from_clkspec() 2025-05-02 07:39:28 +02:00
clocksource clocksource/i8253: Use raw_spinlock_irqsave() in clockevent_i8253_disable() 2025-06-04 14:32:29 +02:00
connector
counter counter: stm32-lptimer-cnt: fix error handling when enabling 2025-04-10 14:29:39 +02:00
cpufreq cpufreq: scpi: Fix null-ptr-deref in scpi_cpufreq_get_rate() 2025-05-02 07:39:25 +02:00
cpuidle cpuidle: menu: Avoid discarding useful information 2025-06-04 14:32:32 +02:00
crypto crypto: marvell/cesa - Avoid empty transfer descriptor 2025-06-27 11:02:45 +01:00
dax
dca
devfreq
dio
dma dmaengine: Revert "dmaengine: dmatest: Fix dmatest waiting less when interrupted" 2025-06-04 14:32:29 +02:00
dma-buf udmabuf: fix a buf size overflow issue during udmabuf creation 2025-05-02 07:39:29 +02:00
edac EDAC/altera: Use correct write width with the INTTEST register 2025-06-27 11:02:51 +01:00
eisa
extcon
firewire
firmware firmware: psci: Fix refcount leak in psci_dt_init 2025-06-27 11:02:46 +01:00
fpga fpga: altera-cvp: Increase credit timeout 2025-06-04 14:32:32 +02:00
fsi
gnss
gpio gpio: zynq: Fix wakeup source leaks on device unbind 2025-05-02 07:39:17 +02:00
gpu drm/amd/display: Do not add '-mhard-float' to dcn2{1,0}_resource.o for clang 2025-06-27 11:02:50 +01:00
greybus
hid HID: quirks: Add ADATA XPG alpha wireless mouse support 2025-06-04 14:32:37 +02:00
hsi HSI: ssi_protocol: Fix use after free vulnerability in ssi_protocol Driver Due to Race Condition 2025-05-02 07:39:18 +02:00
hv Drivers: hv: vmbus: Don't release fb_mmio resource in vmbus_free_mmio() 2025-04-10 14:29:35 +02:00
hwmon hwmon: (xgene-hwmon) use appropriate type for the latency value 2025-06-04 14:32:34 +02:00
hwspinlock
hwtracing coresight: catu: Fix number of pages while using 64k pages 2025-04-10 14:29:41 +02:00
i2c i2c: pxa: fix call balance of i2c->clk handling routines 2025-06-04 14:32:30 +02:00
i3c i3c: Add NULL pointer check in i3c_master_queue_ibi() 2025-05-02 07:39:15 +02:00
ide
idle
iio iio: chemical: sps30: use aligned_s64 for timestamp 2025-06-04 14:32:28 +02:00
infiniband RDMA/hns: Include hnae3.h in hns_roce_hw_v2.h 2025-06-27 11:02:46 +01:00
input Input: ims-pcu - check record size in ims_pcu_flash_firmware() 2025-06-27 11:02:51 +01:00
interconnect
iommu iommu/amd: Fix potential buffer overflow in parse_ivrs_acpihid 2025-06-04 14:32:26 +02:00
ipack
irqchip irqchip/gic-v2m: Prevent use after free of gicv2m_get_fwnode() 2025-06-04 14:32:25 +02:00
isdn
leds leds: lp8860: Write full EEPROM, not only half of it 2025-03-13 12:43:06 +01:00
lightnvm
macintosh
mailbox mailbox: use error ret code of of_parse_phandle_with_args() 2025-06-04 14:32:30 +02:00
mcb mcb: fix a double free bug in chameleon_parse_gdd() 2025-05-02 07:39:26 +02:00
md dm cache: prevent BUG_ON by blocking retries on failed device resumes 2025-06-04 14:32:31 +02:00
media media: v4l2-dev: fix error handling in __video_register_device() 2025-06-27 11:02:51 +01:00
memory
memstick memstick: rtsx_usb_ms: Fix slab-use-after-free in rtsx_usb_ms_drv_remove 2025-04-10 14:29:39 +02:00
message scsi: fusion: Remove unused variable 'rc' 2024-12-14 19:44:29 +01:00
mfd mfd: stmpe-spi: Correct the name used in MODULE_DEVICE_TABLE 2025-06-27 11:02:48 +01:00
misc misc: pci_endpoint_test: Fix displaying 'irq_type' after 'request_irq' error 2025-05-02 07:39:25 +02:00
mmc mmc: sdhci: Disable SD card clock before changing parameters 2025-06-04 14:32:31 +02:00
mtd mtd: rawnand: Add status chack in r852_ready() 2025-05-02 07:39:16 +02:00
mux
net wifi: rtlwifi: disable ASPM for RTL8723BE with subsystem ID 11ad:1723 2025-06-27 11:02:51 +01:00
nfc
ntb ntb: reduce stack usage in idt_scan_mws 2025-05-02 07:39:28 +02:00
nubus
nvdimm libnvdimm/labels: Fix divide error in nd_label_data_init() 2025-06-04 14:32:30 +02:00
nvme nvmet-tcp: don't restore null sk_state_change 2025-06-04 14:32:35 +02:00
nvmem nvmem: core: improve range check for nvmem_cell_write() 2025-03-13 12:43:10 +01:00
of of: module: add buffer overflow check in of_modalias() 2025-06-04 14:32:25 +02:00
opp
oprofile
parisc
parport parport_pc: add support for ASIX AX99100 2025-03-13 12:43:19 +01:00
pci PCI: Fix old_size lower bound in calculate_iosize() too 2025-06-04 14:32:33 +02:00
pcmcia pcmcia: Use resource_size function on resource object 2024-09-12 11:03:52 +02:00
perf perf: arm_pmu: Don't disable counter in armpmu_add() 2025-05-02 07:39:09 +02:00
phy phy: core: don't require set_mode() callback for phy_get_mode() to work 2025-06-04 14:32:33 +02:00
pinctrl pinctrl: at91: Fix possible out-of-boundary access 2025-06-27 11:02:46 +01:00
platform platform/x86: thinkpad_acpi: Ignore battery threshold change event notification 2025-06-04 14:32:37 +02:00
pnp
power power: supply: max77693: Fix wrong conversion of charge input threshold value 2025-04-10 14:29:41 +02:00
powercap powercap: call put_device() on an error path in powercap_register_control_type() 2025-04-10 14:29:36 +02:00
pps pps: Fix a use-after-free 2025-03-13 12:43:19 +01:00
ps3
ptp ptp: Ensure info->enable callback is always set 2025-03-13 12:43:11 +01:00
pwm pwm: mediatek: always use bus clock for PWM on MT7622 2025-05-02 07:39:18 +02:00
rapidio rapidio: fix an API misues when rio_add_net() fails 2025-03-13 12:43:28 +01:00
ras
regulator regulator: ad5398: Add device tree support 2025-06-04 14:32:34 +02:00
remoteproc
reset reset: berlin: fix OF node leak in probe() error path 2024-11-08 16:20:28 +01:00
rpmsg rpmsg: qcom_smd: Fix uninitialized return variable in __qcom_smd_send() 2025-06-27 11:02:48 +01:00
rtc rtc: Fix offset calculation for .start_secs < 0 2025-06-27 11:02:48 +01:00
s390 s390/cio: Fix CHPID "configure" attribute caching 2025-04-10 14:29:36 +02:00
sbus
scsi scsi: iscsi: Fix incorrect error path labels for flashnode operations 2025-06-27 11:02:49 +01:00
sfi
sh sh: clk: Fix clk_enable() to return 0 on NULL clk 2025-01-09 13:23:29 +01:00
siox
slimbus slimbus: messaging: Free transaction ID in delayed interrupt scenario 2025-03-13 12:43:33 +01:00
soc soc: aspeed: Add NULL check in aspeed_lpc_enable_snoop() 2025-06-27 11:02:48 +01:00
soundwire soundwire: stream: Revert "soundwire: stream: fix programming slave ports for non-continous port maps" 2024-11-08 16:20:25 +01:00
spi spi: sh-msiof: Fix maximum DMA transfer size 2025-06-27 11:02:45 +01:00
spmi
ssb
staging staging: axis-fifo: Correct handling of tx_fifo_depth for size validation 2025-06-04 14:32:28 +02:00
target scsi: target: iscsi: Fix timeout on deleted connection 2025-06-04 14:32:29 +02:00
tc
tee tee: optee: Fix supplicant wait loop 2025-03-13 12:43:23 +01:00
thermal thermal/drivers/rockchip: Add missing rk3328 mapping entry 2025-05-02 07:39:16 +02:00
thunderbolt thunderbolt: Do not double dequeue a configuration request 2025-06-27 11:02:44 +01:00
tty vt: remove VT_RESIZE and VT_RESIZEX from vt_compat_ioctl() 2025-06-27 11:02:48 +01:00
uio Drivers: hv: vmbus: Fix rescind handling in uio_hv_generic 2024-09-12 11:03:55 +02:00
usb usb: Flush altsetting 0 endpoints before reinitializating them after reset. 2025-06-27 11:02:50 +01:00
vfio vfio/pci: Enable iowrite64 and ioread64 for vfio pci 2025-03-13 12:43:13 +01:00
vhost
video vgacon: Add check for vc_origin address range in vgacon_scroll() 2025-06-27 11:02:51 +01:00
virt
virtio
visorbus
vlynq
vme
w1
watchdog watchdog: mediatek: Make sure system reset gets asserted in mtk_wdt_restart() 2024-12-14 19:44:44 +01:00
xen xen/swiotlb: relax alignment requirements 2025-06-04 14:32:37 +02:00
zorro
Kconfig
Makefile