No description
  • C 98.2%
  • Assembly 1%
  • Makefile 0.3%
  • Shell 0.2%
  • Python 0.1%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Jann Horn 7cfb70e97f usb: cdc-acm: Fix handling of oversized fragments
commit 12e712964f41d05ae034989892de445781c46730 upstream.

If we receive an initial fragment of size 8 bytes which specifies a wLength
of 1 byte (so the reassembled message is supposed to be 9 bytes long), and
we then receive a second fragment of size 9 bytes (which is not supposed to
happen), we currently wrongly bypass the fragment reassembly code but still
pass the pointer to the acm->notification_buffer to
acm_process_notification().

Make this less wrong by always going through fragment reassembly when we
expect more fragments.

Before this patch, receiving an overlong fragment could lead to `newctrl`
in acm_process_notification() being uninitialized data (instead of data
coming from the device).

Cc: stable <stable@kernel.org>
Fixes: ea2583529c ("cdc-acm: reassemble fragmented notifications")
Signed-off-by: Jann Horn <jannh@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-03-13 12:43:15 +01:00
arch Grab mm lock before grabbing pt lock 2025-03-13 12:43:13 +01:00
block partitions: ldm: remove the initial kernel-doc notation 2025-03-13 12:42:52 +01:00
certs
crypto crypto: pcrypt - Call crypto layer directly when padata_do_parallel() return -EBUSY 2024-12-14 19:44:23 +01:00
Documentation dt-bindings: mmc: controller: clarify the address-cells description 2025-03-13 12:42:53 +01:00
drivers usb: cdc-acm: Fix handling of oversized fragments 2025-03-13 12:43:15 +01:00
fs orangefs: fix a oob in orangefs_debug_write 2025-03-13 12:43:13 +01:00
include vrf: use RCU protection in l3mdev_l3_out() 2025-03-13 12:43:12 +01:00
init initramfs: avoid filename buffer overrun 2024-12-14 19:44:21 +01:00
ipc
kernel tasklet: Introduce new initialization API 2025-03-13 12:43:04 +01:00
lib lib: string_helpers: silence snprintf() output truncation warning 2024-12-14 19:44:39 +01:00
LICENSES
mm mm: vmscan: account for free pages to prevent infinite Loop in throttle_direct_reclaim() 2025-01-09 13:23:37 +01:00
net batman-adv: fix panic during interface removal 2025-03-13 12:43:14 +01:00
samples samples/bpf: Fix a resource leak 2024-12-14 19:44:50 +01:00
scripts kbuild: Move -Wenum-enum-conversion to W=2 2025-03-13 12:43:09 +01:00
security tomoyo: don't emit warning in tomoyo_write_control() 2025-03-13 12:43:03 +01:00
sound ASoC: Intel: bytcr_rt5640: Add DMI quirk for Vexia Edu Atla 10 tablet 5V 2025-03-13 12:43:13 +01:00
tools perf bench: Fix undefined behavior in cmpworker() 2025-03-13 12:43:08 +01:00
usr
virt KVM: arm64: Ignore PMCNTENSET_EL0 while checking for overflow status 2024-12-19 18:05:04 +01:00
.clang-format
.cocciconfig
.get_maintainer.ignore
.gitattributes
.gitignore Remove *.orig pattern from .gitignore 2024-11-08 16:20:33 +01:00
.mailmap
COPYING
CREDITS
Kbuild
Kconfig
MAINTAINERS
Makefile kbuild: userprogs: use correct lld when linking through clang 2025-03-13 12:43:04 +01:00
README

Linux kernel
============

There are several guides for kernel developers and users. These guides can
be rendered in a number of formats, like HTML and PDF. Please read
Documentation/admin-guide/README.rst first.

In order to build the documentation, use ``make htmldocs`` or
``make pdfdocs``.  The formatted documentation can also be read online at:

    https://www.kernel.org/doc/html/latest/

There are various text files in the Documentation/ subdirectory,
several of them using the Restructured Text markup notation.

Please read the Documentation/process/changes.rst file, as it contains the
requirements for building and running the kernel, and information about
the problems which may result by upgrading your kernel.