All of lore.kernel.org
 help / color / mirror / Atom feed
From: Sasha Levin <sashal@kernel.org>
To: linux-kernel@vger.kernel.org, stable@vger.kernel.org
Cc: Xu Jia <xujia39@huawei.com>, Hulk Robot <hulkci@huawei.com>,
	"David S . Miller" <davem@davemloft.net>,
	Sasha Levin <sashal@kernel.org>,
	ajk@comnets.uni-bremen.de, edumazet@google.com, kuba@kernel.org,
	pabeni@redhat.com, linux-hams@vger.kernel.org,
	netdev@vger.kernel.org
Subject: [PATCH AUTOSEL 5.15 16/41] hamradio: 6pack: fix array-index-out-of-bounds in decode_std_command()
Date: Mon, 27 Jun 2022 22:20:35 -0400	[thread overview]
Message-ID: <20220628022100.595243-16-sashal@kernel.org> (raw)
In-Reply-To: <20220628022100.595243-1-sashal@kernel.org>

From: Xu Jia <xujia39@huawei.com>

[ Upstream commit 2b04495e21cdb9b45c28c6aeb2da560184de20a3 ]

Hulk Robot reports incorrect sp->rx_count_cooked value in decode_std_command().
This should be caused by the subtracting from sp->rx_count_cooked before.
It seems that sp->rx_count_cooked value is changed to 0, which bypassed the
previous judgment.

The situation is shown below:

         (Thread 1)			|  (Thread 2)
decode_std_command()		| resync_tnc()
...					|
if (rest == 2)			|
	sp->rx_count_cooked -= 2;	|
else if (rest == 3)			| ...
					| sp->rx_count_cooked = 0;
	sp->rx_count_cooked -= 1;	|
for (i = 0; i < sp->rx_count_cooked; i++) // report error
	checksum += sp->cooked_buf[i];

sp->rx_count_cooked is a shared variable but is not protected by a lock.
The same applies to sp->rx_count. This patch adds a lock to fix the bug.

The fail log is shown below:
=======================================================================
UBSAN: array-index-out-of-bounds in drivers/net/hamradio/6pack.c:925:31
index 400 is out of range for type 'unsigned char [400]'
CPU: 3 PID: 7433 Comm: kworker/u10:1 Not tainted 5.18.0-rc5-00163-g4b97bac0756a #2
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.14.0-0-g155821a1990b-prebuilt.qemu.org 04/01/2014
Workqueue: events_unbound flush_to_ldisc
Call Trace:
 <TASK>
 dump_stack_lvl+0xcd/0x134
 ubsan_epilogue+0xb/0x50
 __ubsan_handle_out_of_bounds.cold+0x62/0x6c
 sixpack_receive_buf+0xfda/0x1330
 tty_ldisc_receive_buf+0x13e/0x180
 tty_port_default_receive_buf+0x6d/0xa0
 flush_to_ldisc+0x213/0x3f0
 process_one_work+0x98f/0x1620
 worker_thread+0x665/0x1080
 kthread+0x2e9/0x3a0
 ret_from_fork+0x1f/0x30
 ...

Reported-by: Hulk Robot <hulkci@huawei.com>
Signed-off-by: Xu Jia <xujia39@huawei.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/net/hamradio/6pack.c | 9 ++++++++-
 1 file changed, 8 insertions(+), 1 deletion(-)

diff --git a/drivers/net/hamradio/6pack.c b/drivers/net/hamradio/6pack.c
index 36a9fbb70402..ac2e79f0a928 100644
--- a/drivers/net/hamradio/6pack.c
+++ b/drivers/net/hamradio/6pack.c
@@ -99,6 +99,7 @@ struct sixpack {
 
 	unsigned int		rx_count;
 	unsigned int		rx_count_cooked;
+	spinlock_t		rxlock;
 
 	int			mtu;		/* Our mtu (to spot changes!) */
 	int			buffsize;       /* Max buffers sizes */
@@ -565,6 +566,7 @@ static int sixpack_open(struct tty_struct *tty)
 	sp->dev = dev;
 
 	spin_lock_init(&sp->lock);
+	spin_lock_init(&sp->rxlock);
 	refcount_set(&sp->refcnt, 1);
 	init_completion(&sp->dead);
 
@@ -913,6 +915,7 @@ static void decode_std_command(struct sixpack *sp, unsigned char cmd)
 			sp->led_state = 0x60;
 			/* fill trailing bytes with zeroes */
 			sp->tty->ops->write(sp->tty, &sp->led_state, 1);
+			spin_lock_bh(&sp->rxlock);
 			rest = sp->rx_count;
 			if (rest != 0)
 				 for (i = rest; i <= 3; i++)
@@ -930,6 +933,7 @@ static void decode_std_command(struct sixpack *sp, unsigned char cmd)
 				sp_bump(sp, 0);
 			}
 			sp->rx_count_cooked = 0;
+			spin_unlock_bh(&sp->rxlock);
 		}
 		break;
 	case SIXP_TX_URUN: printk(KERN_DEBUG "6pack: TX underrun\n");
@@ -959,8 +963,11 @@ sixpack_decode(struct sixpack *sp, const unsigned char *pre_rbuff, int count)
 			decode_prio_command(sp, inbyte);
 		else if ((inbyte & SIXP_STD_CMD_MASK) != 0)
 			decode_std_command(sp, inbyte);
-		else if ((sp->status & SIXP_RX_DCD_MASK) == SIXP_RX_DCD_MASK)
+		else if ((sp->status & SIXP_RX_DCD_MASK) == SIXP_RX_DCD_MASK) {
+			spin_lock_bh(&sp->rxlock);
 			decode_data(sp, inbyte);
+			spin_unlock_bh(&sp->rxlock);
+		}
 	}
 }
 
-- 
2.35.1


  parent reply	other threads:[~2022-06-28  2:20 UTC|newest]

Thread overview: 66+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2022-06-28  2:20 [PATCH AUTOSEL 5.15 01/41] spi: spi-cadence: Fix SPI CS gets toggling sporadically Sasha Levin
2022-06-28  2:20 ` [PATCH AUTOSEL 5.15 02/41] spi: cadence: Detect transmit FIFO depth Sasha Levin
2022-06-28  2:20 ` [PATCH AUTOSEL 5.15 03/41] spi: spi-mem: Fix spi_mem_poll_status() Sasha Levin
2022-06-28  2:20 ` [PATCH AUTOSEL 5.15 04/41] regulator: qcom_smd: correct MP5496 ranges Sasha Levin
2022-06-28  2:20 ` [PATCH AUTOSEL 5.15 05/41] ALSA: usb-audio: US16x08: Move overflow check before array access Sasha Levin
2022-06-28  2:20   ` Sasha Levin
2022-06-28  2:20 ` [PATCH AUTOSEL 5.15 06/41] bus: bt1-apb: Don't print error on -EPROBE_DEFER Sasha Levin
2022-06-28  2:20 ` [PATCH AUTOSEL 5.15 07/41] bus: bt1-axi: " Sasha Levin
2022-06-28  2:20 ` [PATCH AUTOSEL 5.15 08/41] drm/vc4: plane: Prevent async update if we don't have a dlist Sasha Levin
2022-06-28  2:20   ` Sasha Levin
2022-06-28  2:20 ` [PATCH AUTOSEL 5.15 09/41] drm/vc4: crtc: Use an union to store the page flip callback Sasha Levin
2022-06-28  2:20   ` Sasha Levin
2022-06-28  2:20 ` [PATCH AUTOSEL 5.15 10/41] drm/vc4: crtc: Move the BO handling out of common page-flip callback Sasha Levin
2022-06-28  2:20   ` Sasha Levin
2022-06-28  2:20 ` [PATCH AUTOSEL 5.15 11/41] selftests: vm: Fix resource leak when return error Sasha Levin
2022-06-28  2:20 ` [PATCH AUTOSEL 5.15 12/41] scsi: ufs: Simplify ufshcd_clear_cmd() Sasha Levin
2022-06-28  2:20   ` Sasha Levin
2022-06-28  2:20 ` [PATCH AUTOSEL 5.15 13/41] scsi: ufs: Support clearing multiple commands at once Sasha Levin
2022-06-28  2:20   ` Sasha Levin
2022-06-28  2:20 ` [PATCH AUTOSEL 5.15 14/41] ALSA: x86: intel_hdmi_audio: enable pm_runtime and set autosuspend delay Sasha Levin
2022-06-28  2:20   ` Sasha Levin
2022-06-28  2:20 ` [PATCH AUTOSEL 5.15 15/41] ALSA: x86: intel_hdmi_audio: use pm_runtime_resume_and_get() Sasha Levin
2022-06-28  2:20   ` Sasha Levin
2022-06-28  2:20 ` Sasha Levin [this message]
2022-06-28  2:20 ` [PATCH AUTOSEL 5.15 17/41] drivers/net/ethernet/neterion/vxge: Fix a use-after-free bug in vxge-main.c Sasha Levin
2022-06-28  2:20 ` [PATCH AUTOSEL 5.15 18/41] powerpc/prom_init: Fix build failure with GCC_PLUGIN_STRUCTLEAK_BYREF_ALL and KASAN Sasha Levin
2022-06-28  2:20   ` Sasha Levin
2022-06-28  2:20 ` [PATCH AUTOSEL 5.15 19/41] spi: rockchip: Unmask IRQ at the final to avoid preemption Sasha Levin
2022-06-28  2:20   ` Sasha Levin
2022-06-28  2:20   ` Sasha Levin
2022-06-28  2:20 ` [PATCH AUTOSEL 5.15 20/41] video: fbdev: skeletonfb: Fix syntax errors in comments Sasha Levin
2022-06-28  2:20   ` Sasha Levin
2022-06-28  2:20 ` [PATCH AUTOSEL 5.15 21/41] video: fbdev: intelfb: Use aperture size from pci_resource_len Sasha Levin
2022-06-28  2:20   ` Sasha Levin
2022-06-28  2:20 ` [PATCH AUTOSEL 5.15 22/41] video: fbdev: pxa3xx-gcu: Fix integer overflow in pxa3xx_gcu_write Sasha Levin
2022-06-28  2:20   ` Sasha Levin
2022-09-19  8:21   ` Vitaly Chikunov
2022-09-19 22:24     ` Sasha Levin
2022-09-21  5:10       ` Vitaly Chikunov
2022-06-28  2:20 ` [PATCH AUTOSEL 5.15 23/41] video: fbdev: simplefb: Check before clk_put() not needed Sasha Levin
2022-06-28  2:20   ` Sasha Levin
2022-06-28  2:20 ` [PATCH AUTOSEL 5.15 24/41] btrfs: add missing inode updates on each iteration when replacing extents Sasha Levin
2022-06-28  2:20 ` [PATCH AUTOSEL 5.15 25/41] btrfs: do not BUG_ON() on failure to migrate space " Sasha Levin
2022-06-28  2:20 ` [PATCH AUTOSEL 5.15 26/41] io_uring: fix merge error in checking send/recv addr2 flags Sasha Levin
2022-06-28  2:20 ` [PATCH AUTOSEL 5.15 27/41] arch: mips: generic: Add missing of_node_put() in board-ranchu.c Sasha Levin
2022-06-28  2:20 ` [PATCH AUTOSEL 5.15 28/41] mips: mti-malta: Fix refcount leak in malta-time.c Sasha Levin
2022-06-28  2:20 ` [PATCH AUTOSEL 5.15 29/41] mips: ralink: Fix refcount leak in of.c Sasha Levin
2022-06-28  2:20 ` [PATCH AUTOSEL 5.15 30/41] mips: lantiq: falcon: Fix refcount leak bug in sysctrl Sasha Levin
2022-06-28  2:20 ` [PATCH AUTOSEL 5.15 31/41] mips: lantiq: xway: " Sasha Levin
2022-06-28  2:20 ` [PATCH AUTOSEL 5.15 32/41] mips/pic32/pic32mzda: Fix refcount leak bugs Sasha Levin
2022-06-28  2:20 ` [PATCH AUTOSEL 5.15 33/41] mips: dts: ingenic: Add TCU clock to x1000/x1830 tcu device node Sasha Levin
2022-06-28  2:20 ` [PATCH AUTOSEL 5.15 34/41] mips: lantiq: Add missing of_node_put() in irq.c Sasha Levin
2022-06-28  2:20 ` [PATCH AUTOSEL 5.15 35/41] drm/sun4i: Add DMA mask and segment size Sasha Levin
2022-06-28  2:20   ` Sasha Levin
2022-06-28  2:20   ` Sasha Levin
2022-06-28  2:20 ` [PATCH AUTOSEL 5.15 36/41] drm/sun4i: Return if frontend is not present Sasha Levin
2022-06-28  2:20   ` Sasha Levin
2022-06-28  2:20   ` Sasha Levin
2022-06-28  2:20 ` [PATCH AUTOSEL 5.15 37/41] hinic: Replace memcpy() with direct assignment Sasha Levin
2022-06-28  2:20 ` [PATCH AUTOSEL 5.15 38/41] drm/amdgpu: Adjust logic around GTT size (v3) Sasha Levin
2022-06-28  2:20   ` Sasha Levin
2022-06-28  2:20   ` Sasha Levin
2022-06-28  2:20 ` [PATCH AUTOSEL 5.15 39/41] nvme: add a bogus subsystem NQN quirk for Micron MTFDKBA2T0TFH Sasha Levin
2022-06-28  2:20 ` [PATCH AUTOSEL 5.15 40/41] gpio: grgpio: Fix device removing Sasha Levin
2022-06-28  2:21 ` [PATCH AUTOSEL 5.15 41/41] arm: mach-spear: Add missing of_node_put() in time.c Sasha Levin
2022-06-28  2:21   ` Sasha Levin

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20220628022100.595243-16-sashal@kernel.org \
    --to=sashal@kernel.org \
    --cc=ajk@comnets.uni-bremen.de \
    --cc=davem@davemloft.net \
    --cc=edumazet@google.com \
    --cc=hulkci@huawei.com \
    --cc=kuba@kernel.org \
    --cc=linux-hams@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=stable@vger.kernel.org \
    --cc=xujia39@huawei.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.