]> git.baikalelectronics.ru Git - kernel.git/commit
USB: gadget: u_f: add overflow checks to VLA macros
authorBrooke Basile <brookebasile@gmail.com>
Tue, 25 Aug 2020 13:05:08 +0000 (09:05 -0400)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Tue, 25 Aug 2020 14:02:29 +0000 (16:02 +0200)
commitcbceccc1898bb3bb7397987bf69d4eaeafa8177b
treeefcb72facdda141d12b4f43b1cf6279d5cfa49c1
parent6f1ca888dc8b11dfed8da8b78e0691ff486a8c91
USB: gadget: u_f: add overflow checks to VLA macros

size can potentially hold an overflowed value if its assigned expression
is left unchecked, leading to a smaller than needed allocation when
vla_group_size() is used by callers to allocate memory.
To fix this, add a test for saturation before declaring variables and an
overflow check to (n) * sizeof(type).
If the expression results in overflow, vla_group_size() will return SIZE_MAX.

Reported-by: Ilja Van Sprundel <ivansprundel@ioactive.com>
Suggested-by: Kees Cook <keescook@chromium.org>
Signed-off-by: Brooke Basile <brookebasile@gmail.com>
Acked-by: Felipe Balbi <balbi@kernel.org>
Cc: stable <stable@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
drivers/usb/gadget/u_f.h