From: Stefan Richter <stefanr@s5r6.in-berlin.de>
To: Jann Horn <jannh@google.com>
Cc: Randy Dunlap <rdunlap@infradead.org>,
linux1394-devel@lists.sourceforge.net,
kernel list <linux-kernel@vger.kernel.org>
Subject: Re: [PATCH] firewire: nosy: don't read packets bigger than requested
Date: Tue, 18 Sep 2018 16:02:05 +0200 [thread overview]
Message-ID: <20180918160205.1e636d40@kant> (raw)
In-Reply-To: <cbf4c05d-94f2-6ef0-0c90-1f5823329bbb@infradead.org>
On Sep 03 Randy Dunlap wrote:
> On 09/03/2018 08:55 AM, Jann Horn wrote:
> > On Fri, Jul 6, 2018 at 5:16 PM Jann Horn <jannh@google.com> wrote:
> >> In general, accessing userspace memory beyond the length of the supplied
> >> buffer in VFS read/write handlers can lead to both kernel memory corruption
> >> (via kernel_read()/kernel_write(), which can e.g. be triggered via
> >> sys_splice()) and privilege escalation inside userspace.
> >>
> >> Fixes: 286468210d83 ("firewire: new driver: nosy - IEEE 1394 traffic sniffer")
> >> Signed-off-by: Jann Horn <jannh@google.com>
[...]
> >> drivers/firewire/nosy.c | 5 +++--
> >> 1 file changed, 3 insertions(+), 2 deletions(-)
[...]
> > Ping. I sent this about two months ago, I haven't received a reply,
> > and from what I can tell, it hasn't landed in any tree so far...
> >
>
> :(
> I have that same problem with some Firewire documentation patches.
> I plan to ask someone else to merge my patches.
Jann,
sorry for not responding in July (was buried in other work and been
effectively absent from maintainership for many months). And sorry for
missing your ping in September (it must have been misplaced into the spam
folder and I apparently overlooked it there).
This week is another one in which I will not be able to check your patch.
Next week I will have a vacation of sorts and will use it to (a) review
and merge your patch and (b) clean out my mailbox and update my mail
sorting filters (long overdue after my mail service provider changed
backends).
Again sorry, and thank you for your extraordinary patience.
--
Stefan Richter
-======---=- =--= =--=-
http://arcgraph.de/sr/
prev parent reply other threads:[~2018-09-18 14:17 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2018-07-06 15:16 [PATCH] firewire: nosy: don't read packets bigger than requested Jann Horn
2018-09-03 15:55 ` Jann Horn
2018-09-03 15:58 ` Randy Dunlap
2018-09-18 14:02 ` Stefan Richter [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20180918160205.1e636d40@kant \
--to=stefanr@s5r6.in-berlin.de \
--cc=jannh@google.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux1394-devel@lists.sourceforge.net \
--cc=rdunlap@infradead.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox