| From 907767da8f3a925b060c740e0b5c92ea7dbec440 Mon Sep 17 00:00:00 2001 |
| From: Johan Hovold <johan@kernel.org> |
| Date: Wed, 27 Oct 2021 11:35:28 +0200 |
| Subject: comedi: ni_usb6501: fix NULL-deref in command paths |
| |
| From: Johan Hovold <johan@kernel.org> |
| |
| commit 907767da8f3a925b060c740e0b5c92ea7dbec440 upstream. |
| |
| The driver uses endpoint-sized USB transfer buffers but had no sanity |
| checks on the sizes. This can lead to zero-size-pointer dereferences or |
| overflowed transfer buffers in ni6501_port_command() and |
| ni6501_counter_command() if a (malicious) device has smaller max-packet |
| sizes than expected (or when doing descriptor fuzz testing). |
| |
| Add the missing sanity checks to probe(). |
| |
| Fixes: a03bb00e50ab ("staging: comedi: add NI USB-6501 support") |
| Cc: stable@vger.kernel.org # 3.18 |
| Cc: Luca Ellero <luca.ellero@brickedbrain.com> |
| Reviewed-by: Ian Abbott <abbotti@mev.co.uk> |
| Signed-off-by: Johan Hovold <johan@kernel.org> |
| Link: https://lore.kernel.org/r/20211027093529.30896-2-johan@kernel.org |
| Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
| --- |
| drivers/staging/comedi/drivers/ni_usb6501.c | 10 ++++++++++ |
| 1 file changed, 10 insertions(+) |
| |
| --- a/drivers/staging/comedi/drivers/ni_usb6501.c |
| +++ b/drivers/staging/comedi/drivers/ni_usb6501.c |
| @@ -153,6 +153,10 @@ static const u8 READ_COUNTER_RESPONSE[] |
| 0x00, 0x00, 0x00, 0x02, |
| 0x00, 0x00, 0x00, 0x00}; |
| |
| +/* Largest supported packets */ |
| +static const size_t TX_MAX_SIZE = sizeof(SET_PORT_DIR_REQUEST); |
| +static const size_t RX_MAX_SIZE = sizeof(READ_PORT_RESPONSE); |
| + |
| enum commands { |
| READ_PORT, |
| WRITE_PORT, |
| @@ -510,6 +514,12 @@ static int ni6501_find_endpoints(struct |
| if (!devpriv->ep_rx || !devpriv->ep_tx) |
| return -ENODEV; |
| |
| + if (usb_endpoint_maxp(devpriv->ep_rx) < RX_MAX_SIZE) |
| + return -ENODEV; |
| + |
| + if (usb_endpoint_maxp(devpriv->ep_tx) < TX_MAX_SIZE) |
| + return -ENODEV; |
| + |
| return 0; |
| } |
| |