From: Dmitry Torokhov <dmitry.torokhov-Re5JQEeQqe8AvxtiuMwx3w@public.gmane.org>
To: Vladis Dronov <vdronov-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org>
Cc: linux-input-u79uwXL29TY76Z2rM5mHXA@public.gmane.org,
linux-usb-u79uwXL29TY76Z2rM5mHXA@public.gmane.org
Subject: Re: [PATCH] Input: gtco: fix crash on detecting device without endpoints
Date: Thu, 31 Mar 2016 10:57:35 -0700 [thread overview]
Message-ID: <20160331175735.GD39098@dtor-ws> (raw)
In-Reply-To: <1458326100-14899-1-git-send-email-vdronov-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org>
On Fri, Mar 18, 2016 at 07:35:00PM +0100, Vladis Dronov wrote:
> The gtco driver expects at least one valid endpoint. If given
> malicious descriptors that specify 0 for the number of endpoints,
> it will crash in the probe function. Ensure there is at least
> one endpoint on the interface before using it. Fix minor coding
> style issue.
>
> The full report of this issue can be found here:
> http://seclists.org/bugtraq/2016/Mar/86
>
> Reported-by: Ralf Spenneberg <ralf-bSzMNvQHHtybz89kn3q7ow@public.gmane.org>
> Signed-off-by: Vladis Dronov <vdronov-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org>
Applied, thank you.
> ---
> drivers/input/tablet/gtco.c | 10 +++++++++-
> 1 file changed, 9 insertions(+), 1 deletion(-)
>
> diff --git a/drivers/input/tablet/gtco.c b/drivers/input/tablet/gtco.c
> index 3a7f3a4..7c18249 100644
> --- a/drivers/input/tablet/gtco.c
> +++ b/drivers/input/tablet/gtco.c
> @@ -858,6 +858,14 @@ static int gtco_probe(struct usb_interface *usbinterface,
> goto err_free_buf;
> }
>
> + /* Sanity check that a device has an endpoint */
> + if (usbinterface->altsetting[0].desc.bNumEndpoints < 1) {
> + dev_err(&usbinterface->dev,
> + "Invalid number of endpoints\n");
> + error = -EINVAL;
> + goto err_free_urb;
> + }
> +
> /*
> * The endpoint is always altsetting 0, we know this since we know
> * this device only has one interrupt endpoint
> @@ -879,7 +887,7 @@ static int gtco_probe(struct usb_interface *usbinterface,
> * HID report descriptor
> */
> if (usb_get_extra_descriptor(usbinterface->cur_altsetting,
> - HID_DEVICE_TYPE, &hid_desc) != 0){
> + HID_DEVICE_TYPE, &hid_desc) != 0) {
> dev_err(&usbinterface->dev,
> "Can't retrieve exta USB descriptor to get hid report descriptor length\n");
> error = -EIO;
> --
> 2.5.0
--
Dmitry
--
To unsubscribe from this list: send the line "unsubscribe linux-usb" in
the body of a message to majordomo-u79uwXL29TY76Z2rM5mHXA@public.gmane.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
prev parent reply other threads:[~2016-03-31 17:57 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2016-03-18 18:35 [PATCH] Input: gtco: fix crash on detecting device without endpoints Vladis Dronov
[not found] ` <1458326100-14899-1-git-send-email-vdronov-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org>
2016-03-21 9:04 ` Vladis Dronov
2016-03-31 17:57 ` Dmitry Torokhov [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20160331175735.GD39098@dtor-ws \
--to=dmitry.torokhov-re5jqeeqqe8avxtiumwx3w@public.gmane.org \
--cc=linux-input-u79uwXL29TY76Z2rM5mHXA@public.gmane.org \
--cc=linux-usb-u79uwXL29TY76Z2rM5mHXA@public.gmane.org \
--cc=vdronov-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.