No description
  • C 98.2%
  • Assembly 1%
  • Makefile 0.3%
  • Shell 0.2%
  • Python 0.1%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Aleksandr Mishin c5e0523744 nfc: pn533: Add poll mod list filling check
[ Upstream commit febccb39255f9df35527b88c953b2e0deae50e53 ]

In case of im_protocols value is 1 and tm_protocols value is 0 this
combination successfully passes the check
'if (!im_protocols && !tm_protocols)' in the nfc_start_poll().
But then after pn533_poll_create_mod_list() call in pn533_start_poll()
poll mod list will remain empty and dev->poll_mod_count will remain 0
which lead to division by zero.

Normally no im protocol has value 1 in the mask, so this combination is
not expected by driver. But these protocol values actually come from
userspace via Netlink interface (NFC_CMD_START_POLL operation). So a
broken or malicious program may pass a message containing a "bad"
combination of protocol parameter values so that dev->poll_mod_count
is not incremented inside pn533_poll_create_mod_list(), thus leading
to division by zero.
Call trace looks like:
nfc_genl_start_poll()
  nfc_start_poll()
    ->start_poll()
    pn533_start_poll()

Add poll mod list filling check.

Found by Linux Verification Center (linuxtesting.org) with SVACE.

Fixes: dfccd0f580 ("NFC: pn533: Add some polling entropy")
Signed-off-by: Aleksandr Mishin <amishin@t-argos.ru>
Acked-by: Krzysztof Kozlowski <krzysztof.kozlowski@linaro.org>
Link: https://patch.msgid.link/20240827084822.18785-1-amishin@t-argos.ru
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-04 13:15:04 +02:00
arch openrisc: Call setup_memory() earlier in the init sequence 2024-09-04 13:14:57 +02:00
block
certs
crypto
Documentation overflow: Implement size_t saturating arithmetic helpers 2024-09-04 13:14:51 +02:00
drivers nfc: pn533: Add poll mod list filling check 2024-09-04 13:15:04 +02:00
fs filelock: Correct the filelock owner in fcntl_setlk/fcntl_setlk64 2024-09-04 13:15:02 +02:00
include net: busy-poll: use ktime_get_ns() instead of local_clock() 2024-09-04 13:15:03 +02:00
init
ipc ipc: replace costly bailout check in sysvipc_find_ipc() 2024-09-04 13:15:02 +02:00
kernel cgroup/cpuset: Prevent UAF in proc_cpuset_show() 2024-09-04 13:15:03 +02:00
lib overflow: Implement size_t saturating arithmetic helpers 2024-09-04 13:14:51 +02:00
LICENSES
mm memcg_write_event_control(): fix a user-triggerable oops 2024-09-04 13:14:50 +02:00
net ethtool: check device is present when getting link settings 2024-09-04 13:15:03 +02:00
samples
scripts kbuild: Fix '-S -c' in x86 stack protector scripts 2024-08-19 05:33:53 +02:00
security selinux: fix potential counting error in avc_add_xperms_decision() 2024-09-04 13:14:50 +02:00
sound ALSA: timer: Relax start tick time check for slave timer elements 2024-09-04 13:15:01 +02:00
tools tools: move alignment-related macros to new <linux/align.h> 2024-09-04 13:15:02 +02:00
usr
virt
.clang-format
.cocciconfig
.get_maintainer.ignore
.gitattributes
.gitignore
.mailmap
COPYING
CREDITS
Kbuild
Kconfig
MAINTAINERS
Makefile Linux 5.4.282 2024-08-19 05:33:54 +02:00
README

Linux kernel
============

There are several guides for kernel developers and users. These guides can
be rendered in a number of formats, like HTML and PDF. Please read
Documentation/admin-guide/README.rst first.

In order to build the documentation, use ``make htmldocs`` or
``make pdfdocs``.  The formatted documentation can also be read online at:

    https://www.kernel.org/doc/html/latest/

There are various text files in the Documentation/ subdirectory,
several of them using the Restructured Text markup notation.

Please read the Documentation/process/changes.rst file, as it contains the
requirements for building and running the kernel, and information about
the problems which may result by upgrading your kernel.