From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: linux-kernel@vger.kernel.org
Cc: Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
stable@vger.kernel.org,
Stephen Douthit <stephend@adiengineering.com>,
Dan Priamo <danp@adiengineering.com>,
Neil Horman <nhorman@tuxdriver.com>,
Wolfram Sang <wsa@the-dreams.de>
Subject: [PATCH 4.9 03/18] i2c: ismt: Return EMSGSIZE for block reads with bogus length
Date: Tue, 5 Sep 2017 09:11:11 +0200 [thread overview]
Message-ID: <20170905070918.195182116@linuxfoundation.org> (raw)
In-Reply-To: <20170905070918.034746210@linuxfoundation.org>
4.9-stable review patch. If anyone has any objections, please let me know.
------------------
From: Stephen Douthit <stephend@adiengineering.com>
commit ba201c4f5ebe13d7819081756378777d8153f23e upstream.
Compare the number of bytes actually seen on the wire to the byte
count field returned by the slave device.
Previously we just overwrote the byte count returned by the slave
with the real byte count and let the caller figure out if the
message was sane.
Signed-off-by: Stephen Douthit <stephend@adiengineering.com>
Tested-by: Dan Priamo <danp@adiengineering.com>
Acked-by: Neil Horman <nhorman@tuxdriver.com>
Signed-off-by: Wolfram Sang <wsa@the-dreams.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/i2c/busses/i2c-ismt.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
--- a/drivers/i2c/busses/i2c-ismt.c
+++ b/drivers/i2c/busses/i2c-ismt.c
@@ -341,8 +341,10 @@ static int ismt_process_desc(const struc
break;
case I2C_SMBUS_BLOCK_DATA:
case I2C_SMBUS_I2C_BLOCK_DATA:
+ if (desc->rxbytes != dma_buffer[0] + 1)
+ return -EMSGSIZE;
+
memcpy(data->block, dma_buffer, desc->rxbytes);
- data->block[0] = desc->rxbytes - 1;
break;
}
return 0;
next prev parent reply other threads:[~2017-09-05 7:11 UTC|newest]
Thread overview: 21+ messages / expand[flat|nested] mbox.gz Atom feed top
2017-09-05 7:11 [PATCH 4.9 00/18] 4.9.48-stable review Greg Kroah-Hartman
2017-09-05 7:11 ` [PATCH 4.9 01/18] irqchip: mips-gic: SYNC after enabling GIC region Greg Kroah-Hartman
2017-09-05 7:11 ` [PATCH 4.9 02/18] i2c: ismt: Dont duplicate the receive length for block reads Greg Kroah-Hartman
2017-09-05 7:11 ` Greg Kroah-Hartman [this message]
2017-09-05 7:11 ` [PATCH 4.9 04/18] crypto: algif_skcipher - only call put_page on referenced and used pages Greg Kroah-Hartman
2017-09-05 7:11 ` [PATCH 4.9 05/18] mm, uprobes: fix multiple free of ->uprobes_state.xol_area Greg Kroah-Hartman
2017-09-05 7:11 ` [PATCH 4.9 06/18] mm, madvise: ensure poisoned pages are removed from per-cpu lists Greg Kroah-Hartman
2017-09-05 7:11 ` [PATCH 4.9 07/18] ceph: fix readpage from fscache Greg Kroah-Hartman
2017-09-05 7:11 ` [PATCH 4.9 08/18] cpumask: fix spurious cpumask_of_node() on non-NUMA multi-node configs Greg Kroah-Hartman
2017-09-05 7:11 ` [PATCH 4.9 09/18] cpuset: Fix incorrect memory_pressure control file mapping Greg Kroah-Hartman
2017-09-05 7:11 ` [PATCH 4.9 10/18] alpha: uapi: Add support for __SANE_USERSPACE_TYPES__ Greg Kroah-Hartman
2017-09-05 7:11 ` [PATCH 4.9 11/18] CIFS: Fix maximum SMB2 header size Greg Kroah-Hartman
2017-09-05 7:11 ` [PATCH 4.9 12/18] CIFS: remove endian related sparse warning Greg Kroah-Hartman
2017-09-05 7:11 ` [PATCH 4.9 13/18] wl1251: add a missing spin_lock_init() Greg Kroah-Hartman
2017-09-05 7:11 ` [PATCH 4.9 14/18] lib/mpi: kunmap after finishing accessing buffer Greg Kroah-Hartman
2017-09-05 7:11 ` [PATCH 4.9 15/18] xfrm: policy: check policy direction value Greg Kroah-Hartman
2017-09-05 7:11 ` [PATCH 4.9 17/18] kvm: arm/arm64: Force reading uncached stage2 PGD Greg Kroah-Hartman
2017-09-05 9:29 ` [PATCH 4.9 00/18] 4.9.48-stable review Sumit Semwal
2017-09-05 14:15 ` Greg Kroah-Hartman
2017-09-05 16:48 ` Guenter Roeck
2017-09-05 17:14 ` Shuah Khan
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20170905070918.195182116@linuxfoundation.org \
--to=gregkh@linuxfoundation.org \
--cc=danp@adiengineering.com \
--cc=linux-kernel@vger.kernel.org \
--cc=nhorman@tuxdriver.com \
--cc=stable@vger.kernel.org \
--cc=stephend@adiengineering.com \
--cc=wsa@the-dreams.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).