* [PATCH v2] usb: storage: sierra_ms: reject short SWoC info transfers
@ 2026-09-10 14:03 Syed Labeeq Sajid Bukhari
2026-09-10 15:51 ` [usb-storage] " Alan Stern
0 siblings, 1 reply; 2+ messages in thread
From: Syed Labeeq Sajid Bukhari @ 2026-09-10 14:03 UTC (permalink / raw)
To: linux-usb, usb-storage; +Cc: stern, gregkh, Syed Labeeq Sajid Bukhari, stable
sierra_get_swoc_info() requests sizeof(struct swoc_info) (60) bytes
from the device via usb_control_msg(), but its callers only treat a
negative return value as failure. A device that answers the
vendor-specific GetSwocInfo request with a short IN transfer is
therefore accepted, leaving the tail of the freshly allocated
(kmalloc(), non-zeroing) swoc_info buffer uninitialized.
truinst_show() subsequently prints swocInfo->rev, swocInfo->LinuxSKU
and swocInfo->LinuxVer from that buffer into the world-readable
(0444) "truinst" sysfs attribute. An emulated/malicious USB device
(VID 0x1199, PID 0x0fff) can exploit this to disclose up to 5 bytes
of stale kernel heap memory (kmalloc-64) to unprivileged userspace,
once per sysfs read, indefinitely. On kernels built without
init_on_alloc this leaks recently freed heap contents.
Only accept the transfer when the full structure was received.
sierra_ms_init() already retries failed queries, so well-behaved
devices are unaffected.
Fixes: 32fe5e393455 ("USB Storage Sierra: TRU-Install feature update")
Cc: stable@vger.kernel.org
Signed-off-by: Syed Labeeq Sajid Bukhari <syedlabeeq@gmail.com>
Assisted-by: Kimi:K2 [Kimi Code CLI]
---
v2: add blank line before the comment block; add Assisted-by tag.
No functional change.
drivers/usb/storage/sierra_ms.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/drivers/usb/storage/sierra_ms.c b/drivers/usb/storage/sierra_ms.c
index 177fa6cd143ab2837640c26f8336781ddd3cf9cb..d8fe9561b2b5f4cce6aa8702309cfc195bc3c891 100644
--- a/drivers/usb/storage/sierra_ms.c
+++ b/drivers/usb/storage/sierra_ms.c
@@ -77,6 +77,13 @@
sizeof(struct swoc_info), /* __u16 size */
USB_CTRL_SET_TIMEOUT); /* int timeout */
+ /*
+ * A short IN transfer leaves the tail of swocInfo uninitialized;
+ * only a full transfer is valid.
+ */
+ if (result != sizeof(struct swoc_info))
+ return -EIO;
+
swocInfo->LinuxSKU = le16_to_cpu(swocInfo->LinuxSKU);
swocInfo->LinuxVer = le16_to_cpu(swocInfo->LinuxVer);
return result;
--
2.43.0
^ permalink raw reply related [flat|nested] 2+ messages in thread
* Re: [usb-storage] [PATCH v2] usb: storage: sierra_ms: reject short SWoC info transfers
2026-09-10 14:03 [PATCH v2] usb: storage: sierra_ms: reject short SWoC info transfers Syed Labeeq Sajid Bukhari
@ 2026-09-10 15:51 ` Alan Stern
0 siblings, 0 replies; 2+ messages in thread
From: Alan Stern @ 2026-09-10 15:51 UTC (permalink / raw)
To: Syed Labeeq Sajid Bukhari; +Cc: linux-usb, usb-storage, gregkh, stable
On Thu, Sep 10, 2026 at 07:03:43PM +0500, Syed Labeeq Sajid Bukhari wrote:
> sierra_get_swoc_info() requests sizeof(struct swoc_info) (60) bytes
> from the device via usb_control_msg(), but its callers only treat a
> negative return value as failure. A device that answers the
> vendor-specific GetSwocInfo request with a short IN transfer is
> therefore accepted, leaving the tail of the freshly allocated
> (kmalloc(), non-zeroing) swoc_info buffer uninitialized.
>
> truinst_show() subsequently prints swocInfo->rev, swocInfo->LinuxSKU
> and swocInfo->LinuxVer from that buffer into the world-readable
> (0444) "truinst" sysfs attribute. An emulated/malicious USB device
> (VID 0x1199, PID 0x0fff) can exploit this to disclose up to 5 bytes
> of stale kernel heap memory (kmalloc-64) to unprivileged userspace,
> once per sysfs read, indefinitely. On kernels built without
> init_on_alloc this leaks recently freed heap contents.
>
> Only accept the transfer when the full structure was received.
> sierra_ms_init() already retries failed queries, so well-behaved
> devices are unaffected.
>
> Fixes: 32fe5e393455 ("USB Storage Sierra: TRU-Install feature update")
> Cc: stable@vger.kernel.org
> Signed-off-by: Syed Labeeq Sajid Bukhari <syedlabeeq@gmail.com>
> Assisted-by: Kimi:K2 [Kimi Code CLI]
> ---
> v2: add blank line before the comment block; add Assisted-by tag.
> No functional change.
> drivers/usb/storage/sierra_ms.c | 7 +++++++
> 1 file changed, 7 insertions(+)
Acked-by: Alan Stern <stern@rowland.harvard.edu>
> diff --git a/drivers/usb/storage/sierra_ms.c b/drivers/usb/storage/sierra_ms.c
> index 177fa6cd143ab2837640c26f8336781ddd3cf9cb..d8fe9561b2b5f4cce6aa8702309cfc195bc3c891 100644
> --- a/drivers/usb/storage/sierra_ms.c
> +++ b/drivers/usb/storage/sierra_ms.c
> @@ -77,6 +77,13 @@
> sizeof(struct swoc_info), /* __u16 size */
> USB_CTRL_SET_TIMEOUT); /* int timeout */
>
> + /*
> + * A short IN transfer leaves the tail of swocInfo uninitialized;
> + * only a full transfer is valid.
> + */
> + if (result != sizeof(struct swoc_info))
> + return -EIO;
> +
> swocInfo->LinuxSKU = le16_to_cpu(swocInfo->LinuxSKU);
> swocInfo->LinuxVer = le16_to_cpu(swocInfo->LinuxVer);
> return result;
> --
> 2.43.0
>
> --
> You received this message because you are subscribed to the Google Groups "USB Mass Storage on Linux" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to usb-storage+unsubscribe@lists.one-eyed-alien.net.
> To view this discussion visit https://groups.google.com/a/lists.one-eyed-alien.net/d/msgid/usb-storage/20260910140343.49371-1-syedlabeeq%40gmail.com.
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-09-10 15:51 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-10 14:03 [PATCH v2] usb: storage: sierra_ms: reject short SWoC info transfers Syed Labeeq Sajid Bukhari
2026-09-10 15:51 ` [usb-storage] " Alan Stern
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox