| From 2ef2391a700a2a044544e791c08f746fec938d8b Mon Sep 17 00:00:00 2001 |
| From: Sasha Levin <sashal@kernel.org> |
| Date: Wed, 31 Jul 2019 12:19:05 -0300 |
| Subject: media: ttusb-dec: Fix info-leak in ttusb_dec_send_command() |
| |
| From: Tomas Bortoli <tomasbortoli@gmail.com> |
| |
| [ Upstream commit a10feaf8c464c3f9cfdd3a8a7ce17e1c0d498da1 ] |
| |
| The function at issue does not always initialize each byte allocated |
| for 'b' and can therefore leak uninitialized memory to a USB device in |
| the call to usb_bulk_msg() |
| |
| Use kzalloc() instead of kmalloc() |
| |
| Signed-off-by: Tomas Bortoli <tomasbortoli@gmail.com> |
| Reported-by: syzbot+0522702e9d67142379f1@syzkaller.appspotmail.com |
| Signed-off-by: Sean Young <sean@mess.org> |
| Signed-off-by: Mauro Carvalho Chehab <mchehab+samsung@kernel.org> |
| Signed-off-by: Sasha Levin <sashal@kernel.org> |
| --- |
| drivers/media/usb/ttusb-dec/ttusb_dec.c | 2 +- |
| 1 file changed, 1 insertion(+), 1 deletion(-) |
| |
| diff --git a/drivers/media/usb/ttusb-dec/ttusb_dec.c b/drivers/media/usb/ttusb-dec/ttusb_dec.c |
| index 4e7671a3a1e4a..d7397c0d7f869 100644 |
| --- a/drivers/media/usb/ttusb-dec/ttusb_dec.c |
| +++ b/drivers/media/usb/ttusb-dec/ttusb_dec.c |
| @@ -278,7 +278,7 @@ static int ttusb_dec_send_command(struct ttusb_dec *dec, const u8 command, |
| |
| dprintk("%s\n", __func__); |
| |
| - b = kmalloc(COMMAND_PACKET_SIZE + 4, GFP_KERNEL); |
| + b = kzalloc(COMMAND_PACKET_SIZE + 4, GFP_KERNEL); |
| if (!b) |
| return -ENOMEM; |
| |
| -- |
| 2.20.1 |
| |