lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Date: Wed, 11 Jul 2018 15:29:31 +0300 From: Tomas Winkler <tomas.winkler@...el.com> To: Greg Kroah-Hartman <gregkh@...uxfoundation.org> Cc: Alexander Usyskin <alexander.usyskin@...el.com>, linux-kernel@...r.kernel.org, Dan Carpenter <dan.carpenter@...cle.com>, stable@...r.kernel.org, Tomas Winkler <tomas.winkler@...el.com> Subject: [char-misc-next v2 1/2] mei: bus: type promotion bug in mei_nfc_if_version() From: Dan Carpenter <dan.carpenter@...cle.com> We accidentally removed the check for negative returns without considering the issue of type promotion. The "if_version_length" variable is type size_t so if __mei_cl_recv() returns a negative then "bytes_recv" is type promoted to a high positive value and treated as success. Cc: <stable@...r.kernel.org> Fixes: 582ab27a063a ("mei: bus: fix received data size check in NFC fixup") Signed-off-by: Dan Carpenter <dan.carpenter@...cle.com> Signed-off-by: Tomas Winkler <tomas.winkler@...el.com> --- V2: rebase drivers/misc/mei/bus-fixup.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/misc/mei/bus-fixup.c b/drivers/misc/mei/bus-fixup.c index e45fe826d87d..65e28be3c8cc 100644 --- a/drivers/misc/mei/bus-fixup.c +++ b/drivers/misc/mei/bus-fixup.c @@ -341,7 +341,7 @@ static int mei_nfc_if_version(struct mei_cl *cl, ret = 0; bytes_recv = __mei_cl_recv(cl, (u8 *)reply, if_version_length, 0, 0); - if (bytes_recv < if_version_length) { + if (bytes_recv < 0 || bytes_recv < if_version_length) { dev_err(bus->dev, "Could not read IF version\n"); ret = -EIO; goto err; -- 2.14.4
Powered by blists - more mailing lists