No description
  • C 98.2%
  • Assembly 1%
  • Makefile 0.3%
  • Shell 0.2%
  • Python 0.1%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Jann Horn a4e1ae5c05 usb: cdc-acm: Check control transfer buffer size before access
commit e563b01208f4d1f609bcab13333b6c0e24ce6a01 upstream.

If the first fragment is shorter than struct usb_cdc_notification, we can't
calculate an expected_size. Log an error and discard the notification
instead of reading lengths from memory outside the received data, which can
lead to memory corruption when the expected_size decreases between
fragments, causing `expected_size - acm->nb_index` to wrap.

This issue has been present since the beginning of git history; however,
it only leads to memory corruption since commit ea2583529c
("cdc-acm: reassemble fragmented notifications").

A mitigating factor is that acm_ctrl_irq() can only execute after userspace
has opened /dev/ttyACM*; but if ModemManager is running, ModemManager will
do that automatically depending on the USB device's vendor/product IDs and
its other interfaces.

Cc: stable <stable@kernel.org>
Fixes: 1da177e4c3 ("Linux-2.6.12-rc2")
Signed-off-by: Jann Horn <jannh@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-03-13 12:43:15 +01:00
arch Grab mm lock before grabbing pt lock 2025-03-13 12:43:13 +01:00
block partitions: ldm: remove the initial kernel-doc notation 2025-03-13 12:42:52 +01:00
certs
crypto
Documentation dt-bindings: mmc: controller: clarify the address-cells description 2025-03-13 12:42:53 +01:00
drivers usb: cdc-acm: Check control transfer buffer size before access 2025-03-13 12:43:15 +01:00
fs orangefs: fix a oob in orangefs_debug_write 2025-03-13 12:43:13 +01:00
include vrf: use RCU protection in l3mdev_l3_out() 2025-03-13 12:43:12 +01:00
init
ipc
kernel tasklet: Introduce new initialization API 2025-03-13 12:43:04 +01:00
lib
LICENSES
mm mm: vmscan: account for free pages to prevent infinite Loop in throttle_direct_reclaim() 2025-01-09 13:23:37 +01:00
net batman-adv: fix panic during interface removal 2025-03-13 12:43:14 +01:00
samples
scripts kbuild: Move -Wenum-enum-conversion to W=2 2025-03-13 12:43:09 +01:00
security tomoyo: don't emit warning in tomoyo_write_control() 2025-03-13 12:43:03 +01:00
sound ASoC: Intel: bytcr_rt5640: Add DMI quirk for Vexia Edu Atla 10 tablet 5V 2025-03-13 12:43:13 +01:00
tools perf bench: Fix undefined behavior in cmpworker() 2025-03-13 12:43:08 +01:00
usr
virt KVM: arm64: Ignore PMCNTENSET_EL0 while checking for overflow status 2024-12-19 18:05:04 +01:00
.clang-format
.cocciconfig
.get_maintainer.ignore
.gitattributes
.gitignore
.mailmap
COPYING
CREDITS
Kbuild
Kconfig
MAINTAINERS
Makefile kbuild: userprogs: use correct lld when linking through clang 2025-03-13 12:43:04 +01:00
README

Linux kernel
============

There are several guides for kernel developers and users. These guides can
be rendered in a number of formats, like HTML and PDF. Please read
Documentation/admin-guide/README.rst first.

In order to build the documentation, use ``make htmldocs`` or
``make pdfdocs``.  The formatted documentation can also be read online at:

    https://www.kernel.org/doc/html/latest/

There are various text files in the Documentation/ subdirectory,
several of them using the Restructured Text markup notation.

Please read the Documentation/process/changes.rst file, as it contains the
requirements for building and running the kernel, and information about
the problems which may result by upgrading your kernel.