android_kernel_motorola_sm6375/drivers/usb
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Kees Cook da4e715a46 USB: ene_usb6250: Allocate enough memory for full object
[ Upstream commit ce33e64c1788912976b61314b56935abd4bc97ef ]

The allocation of PageBuffer is 512 bytes in size, but the dereferencing
of struct ms_bootblock_idi (also size 512) happens at a calculated offset
within the allocation, which means the object could potentially extend
beyond the end of the allocation. Avoid this case by just allocating
enough space to catch any accesses beyond the end. Seen with GCC 13:

../drivers/usb/storage/ene_ub6250.c: In function 'ms_lib_process_bootblock':
../drivers/usb/storage/ene_ub6250.c:1050:44: warning: array subscript 'struct ms_bootblock_idi[0]' is partly outside array bounds of 'unsigned char[512]' [-Warray-bounds=]
 1050 |                         if (le16_to_cpu(idi->wIDIgeneralConfiguration) != MS_IDI_GENERAL_CONF)
      |                                            ^~
../include/uapi/linux/byteorder/little_endian.h:37:51: note: in definition of macro '__le16_to_cpu'
   37 | #define __le16_to_cpu(x) ((__force __u16)(__le16)(x))
      |                                                   ^
../drivers/usb/storage/ene_ub6250.c:1050:29: note: in expansion of macro 'le16_to_cpu'
 1050 |                         if (le16_to_cpu(idi->wIDIgeneralConfiguration) != MS_IDI_GENERAL_CONF)
      |                             ^~~~~~~~~~~
In file included from ../drivers/usb/storage/ene_ub6250.c:5:
In function 'kmalloc',
    inlined from 'ms_lib_process_bootblock' at ../drivers/usb/storage/ene_ub6250.c:942:15:
../include/linux/slab.h:580:24: note: at offset [256, 512] into object of size 512 allocated by 'kmalloc_trace'
  580 |                 return kmalloc_trace(
      |                        ^~~~~~~~~~~~~~
  581 |                                 kmalloc_caches[kmalloc_type(flags)][index],
      |                                 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  582 |                                 flags, size);
      |                                 ~~~~~~~~~~~~

Cc: Alan Stern <stern@rowland.harvard.edu>
Signed-off-by: Kees Cook <keescook@chromium.org>
Link: https://lore.kernel.org/r/20230204183546.never.849-kees@kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2023-03-11 16:44:15 +01:00
..
atm
c67x00
cdns3
chipidea usb: chipidea: fix deadlock in ci_otg_del_timer 2022-11-25 17:42:18 +01:00
class
common Revert "usb: ulpi: defer ulpi_register on ulpi_read_id timeout" 2023-01-18 11:42:06 +01:00
core USB: core: Don't hold device lock while reading the "descriptors" sysfs file 2023-03-03 11:41:49 +01:00
dwc2
dwc3 usb: dwc3: qcom: enable vbus override when in OTG dr-mode 2023-02-22 12:50:26 +01:00
early
gadget treewide: Replace DECLARE_TASKLET() with DECLARE_TASKLET_OLD() 2023-03-11 16:43:42 +01:00
host usb: host: xhci: mvebu: Iterate over array indexes instead of using pointer math 2023-03-11 16:44:15 +01:00
image
isp1760
misc USB: misc: iowarrior: fix up header size for USB_DEVICE_ID_CODEMERCS_IOW100 2023-01-24 07:18:00 +01:00
mon usb: mon: make mmapped memory read only 2022-10-15 07:54:38 +02:00
mtu3
musb usb: musb: remove extra check in musb_gadget_vbus_draw 2023-01-18 11:40:49 +01:00
phy
renesas_usbhs
roles usb: roles: fix of node refcount leak in usb_role_switch_is_parent() 2023-01-18 11:41:24 +01:00
serial USB: serial: option: add support for VW/Skoda "Carstick LTE" 2023-03-03 11:41:49 +01:00
storage USB: ene_usb6250: Allocate enough memory for full object 2023-03-11 16:44:15 +01:00
typec usb: typec: altmodes/displayport: Fix probe pin assign check 2023-02-22 12:50:33 +01:00
usbip
Kconfig
Makefile
usb-skeleton.c