From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail-wr1-f67.google.com ([209.85.221.67]:34027 "EHLO mail-wr1-f67.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1726902AbeJICcm (ORCPT ); Mon, 8 Oct 2018 22:32:42 -0400 From: Sudip Mukherjee To: Valentina Manea , Shuah Khan , Greg Kroah-Hartman Cc: linux-kernel@vger.kernel.org, linux-usb@vger.kernel.org, syzbot+600b03e0cf1b73bb23c4@syzkaller.appspotmail.com, Sudip Mukherjee , stable Subject: [PATCH] usbip: vhci_hcd: check port number before using Date: Mon, 8 Oct 2018 20:19:13 +0100 Message-Id: <20181008191913.11527-1-sudip.mukherjee@codethink.co.uk> Sender: stable-owner@vger.kernel.org List-ID: From: Sudip Mukherjee The port number is checked and it just prints an error message but it still continues to use the invalid port. And as a result it accesses memory which is not its resulting in BUG report from KASAN. Reported-by: syzbot+600b03e0cf1b73bb23c4@syzkaller.appspotmail.com Cc: stable Signed-off-by: Sudip Mukherjee --- drivers/usb/usbip/vhci_hcd.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/drivers/usb/usbip/vhci_hcd.c b/drivers/usb/usbip/vhci_hcd.c index d11f3f8dad40..71883aa788ac 100644 --- a/drivers/usb/usbip/vhci_hcd.c +++ b/drivers/usb/usbip/vhci_hcd.c @@ -334,8 +334,10 @@ static int vhci_hub_control(struct usb_hcd *hcd, u16 typeReq, u16 wValue, usbip_dbg_vhci_rh("typeReq %x wValue %x wIndex %x\n", typeReq, wValue, wIndex); - if (wIndex > VHCI_HC_PORTS) + if (wIndex > VHCI_HC_PORTS) { pr_err("invalid port number %d\n", wIndex); + return -ENODEV; + } rhport = wIndex - 1; vhci_hcd = hcd_to_vhci_hcd(hcd); -- 2.11.0