All of lore.kernel.org
 help / color / mirror / Atom feed
* USB: wusbcore: crypto: Remove VLA usage
@ 2018-03-16 13:01 ` Gustavo A. R. Silva
  0 siblings, 0 replies; 4+ messages in thread
From: Gustavo A. R. Silva @ 2018-03-16 13:01 UTC (permalink / raw)
  To: Greg Kroah-Hartman; +Cc: linux-usb, linux-kernel, Gustavo A. R. Silva

In preparation to enabling -Wvla, remove VLA and replace it
with dynamic memory allocation instead.

The use of stack Variable Length Arrays needs to be avoided, as they
can be a vector for stack exhaustion, which can be both a runtime bug
or a security flaw. Also, in general, as code evolves it is easy to
lose track of how big a VLA can get. Thus, we can end up having runtime
failures that are hard to debug.

Also, fixed as part of the directive to remove all VLAs from
the kernel: https://lkml.org/lkml/2018/3/7/621

Notice that in this particular case, an alternative to kzalloc is kcalloc,
in which case the code would look as follows instead:

iv = kcalloc(crypto_skcipher_ivsize(tfm_cbc), sizeof(*iv), GFP_KERNEL);

but if the data type of _iv_ never changes, or the type size is always one
byte, kzalloc is good enough.

Signed-off-by: Gustavo A. R. Silva <gustavo@embeddedor.com>
---
 drivers/usb/wusbcore/crypto.c | 11 +++++++----
 1 file changed, 7 insertions(+), 4 deletions(-)

diff --git a/drivers/usb/wusbcore/crypto.c b/drivers/usb/wusbcore/crypto.c
index 4c00be2d..3511473 100644
--- a/drivers/usb/wusbcore/crypto.c
+++ b/drivers/usb/wusbcore/crypto.c
@@ -202,7 +202,7 @@ static int wusb_ccm_mac(struct crypto_skcipher *tfm_cbc,
 	struct scatterlist sg[4], sg_dst;
 	void *dst_buf;
 	size_t dst_size;
-	u8 iv[crypto_skcipher_ivsize(tfm_cbc)];
+	u8 *iv;
 	size_t zero_padding;
 
 	/*
@@ -222,9 +222,11 @@ static int wusb_ccm_mac(struct crypto_skcipher *tfm_cbc,
 		zero_padding;
 	dst_buf = kzalloc(dst_size, GFP_KERNEL);
 	if (!dst_buf)
-		goto error_dst_buf;
+		goto error_alloc;
 
-	memset(iv, 0, sizeof(iv));
+	iv = kzalloc(crypto_skcipher_ivsize(tfm_cbc), GFP_KERNEL);
+	if (!iv)
+		goto error_alloc;
 
 	/* Setup B0 */
 	scratch->b0.flags = 0x59;	/* Format B0 */
@@ -276,8 +278,9 @@ static int wusb_ccm_mac(struct crypto_skcipher *tfm_cbc,
 	bytewise_xor(mic, &scratch->ax, iv, 8);
 	result = 8;
 error_cbc_crypt:
+	kfree(iv);
 	kfree(dst_buf);
-error_dst_buf:
+error_alloc:
 	return result;
 }
 

^ permalink raw reply related	[flat|nested] 4+ messages in thread
* USB: wusbcore: crypto: Remove VLA usage
  2018-03-16 13:01 ` [PATCH] " Gustavo A. R. Silva
@ 2018-03-16 13:19 ` Gustavo A. R. Silva
  -1 siblings, 0 replies; 4+ messages in thread
From: Gustavo A. R. Silva @ 2018-03-16 13:19 UTC (permalink / raw)
  To: Greg Kroah-Hartman; +Cc: linux-usb, linux-kernel

I just discovered an issue with this patch. Please, drop it. I'll send 
v2 shortly.

Thanks
---
Gustavo

On 03/16/2018 08:01 AM, Gustavo A. R. Silva wrote:
> In preparation to enabling -Wvla, remove VLA and replace it
> with dynamic memory allocation instead.
> 
> The use of stack Variable Length Arrays needs to be avoided, as they
> can be a vector for stack exhaustion, which can be both a runtime bug
> or a security flaw. Also, in general, as code evolves it is easy to
> lose track of how big a VLA can get. Thus, we can end up having runtime
> failures that are hard to debug.
> 
> Also, fixed as part of the directive to remove all VLAs from
> the kernel: https://lkml.org/lkml/2018/3/7/621
> 
> Notice that in this particular case, an alternative to kzalloc is kcalloc,
> in which case the code would look as follows instead:
> 
> iv = kcalloc(crypto_skcipher_ivsize(tfm_cbc), sizeof(*iv), GFP_KERNEL);
> 
> but if the data type of _iv_ never changes, or the type size is always one
> byte, kzalloc is good enough.
> 
> Signed-off-by: Gustavo A. R. Silva <gustavo@embeddedor.com>
> ---
>   drivers/usb/wusbcore/crypto.c | 11 +++++++----
>   1 file changed, 7 insertions(+), 4 deletions(-)
> 
> diff --git a/drivers/usb/wusbcore/crypto.c b/drivers/usb/wusbcore/crypto.c
> index 4c00be2d..3511473 100644
> --- a/drivers/usb/wusbcore/crypto.c
> +++ b/drivers/usb/wusbcore/crypto.c
> @@ -202,7 +202,7 @@ static int wusb_ccm_mac(struct crypto_skcipher *tfm_cbc,
>   	struct scatterlist sg[4], sg_dst;
>   	void *dst_buf;
>   	size_t dst_size;
> -	u8 iv[crypto_skcipher_ivsize(tfm_cbc)];
> +	u8 *iv;
>   	size_t zero_padding;
>   
>   	/*
> @@ -222,9 +222,11 @@ static int wusb_ccm_mac(struct crypto_skcipher *tfm_cbc,
>   		zero_padding;
>   	dst_buf = kzalloc(dst_size, GFP_KERNEL);
>   	if (!dst_buf)
> -		goto error_dst_buf;
> +		goto error_alloc;
>   
> -	memset(iv, 0, sizeof(iv));
> +	iv = kzalloc(crypto_skcipher_ivsize(tfm_cbc), GFP_KERNEL);
> +	if (!iv)
> +		goto error_alloc;
>   
>   	/* Setup B0 */
>   	scratch->b0.flags = 0x59;	/* Format B0 */
> @@ -276,8 +278,9 @@ static int wusb_ccm_mac(struct crypto_skcipher *tfm_cbc,
>   	bytewise_xor(mic, &scratch->ax, iv, 8);
>   	result = 8;
>   error_cbc_crypt:
> +	kfree(iv);
>   	kfree(dst_buf);
> -error_dst_buf:
> +error_alloc:
>   	return result;
>   }
>   
> 


--
To unsubscribe from this list: send the line "unsubscribe linux-usb" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2018-03-16 13:25 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2018-03-16 13:01 USB: wusbcore: crypto: Remove VLA usage Gustavo A. R. Silva
2018-03-16 13:01 ` [PATCH] " Gustavo A. R. Silva
  -- strict thread matches above, loose matches on Subject: below --
2018-03-16 13:19 Gustavo A. R. Silva
2018-03-16 13:19 ` [PATCH] " Gustavo A. R. Silva

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.