Commit 0ec74596 authored by Johan Hovold's avatar Johan Hovold Committed by Ben Hutchings

USB: serial: digi_acceleport: fix incomplete rx sanity check

commit 1b0aed2b upstream.

Make sure the received data has the required headers before parsing it.

Also drop the redundant urb-status check, which has already been handled
by the caller.

Fixes: 1da177e4 ("Linux-2.6.12-rc2")
Reviewed-by: default avatarGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: default avatarJohan Hovold <johan@kernel.org>
[bwh: Backported to 3.2: adjust context]
Signed-off-by: default avatarBen Hutchings <ben@decadent.org.uk>
parent 9a1f83c1
...@@ -1660,25 +1660,30 @@ static int digi_read_inb_callback(struct urb *urb) ...@@ -1660,25 +1660,30 @@ static int digi_read_inb_callback(struct urb *urb)
struct usb_serial_port *port = urb->context; struct usb_serial_port *port = urb->context;
struct tty_struct *tty; struct tty_struct *tty;
struct digi_port *priv = usb_get_serial_port_data(port); struct digi_port *priv = usb_get_serial_port_data(port);
int opcode = ((unsigned char *)urb->transfer_buffer)[0]; unsigned char *buf = urb->transfer_buffer;
int len = ((unsigned char *)urb->transfer_buffer)[1]; int opcode;
int port_status = ((unsigned char *)urb->transfer_buffer)[2]; int len;
unsigned char *data = ((unsigned char *)urb->transfer_buffer) + 3; int port_status;
unsigned char *data;
int flag, throttled; int flag, throttled;
int status = urb->status;
/* do not process callbacks on closed ports */
/* but do continue the read chain */
if (urb->status == -ENOENT)
return 0;
/* short/multiple packet check */ /* short/multiple packet check */
if (urb->actual_length < 2) {
dev_warn(&port->dev, "short packet received\n");
return -1;
}
opcode = buf[0];
len = buf[1];
if (urb->actual_length != len + 2) { if (urb->actual_length != len + 2) {
dev_err(&port->dev, "%s: INCOMPLETE OR MULTIPLE PACKET, " dev_err(&port->dev, "malformed packet received: port=%d, opcode=%d, len=%d, actual_length=%u\n",
"status=%d, port=%d, opcode=%d, len=%d, " priv->dp_port_num, opcode, len, urb->actual_length);
"actual_length=%d, status=%d\n", __func__, status, return -1;
priv->dp_port_num, opcode, len, urb->actual_length, }
port_status);
if (opcode == DIGI_CMD_RECEIVE_DATA && len < 1) {
dev_err(&port->dev, "malformed data packet received\n");
return -1; return -1;
} }
...@@ -1693,6 +1698,9 @@ static int digi_read_inb_callback(struct urb *urb) ...@@ -1693,6 +1698,9 @@ static int digi_read_inb_callback(struct urb *urb)
/* receive data */ /* receive data */
if (tty && opcode == DIGI_CMD_RECEIVE_DATA) { if (tty && opcode == DIGI_CMD_RECEIVE_DATA) {
port_status = buf[2];
data = &buf[3];
/* get flag from port_status */ /* get flag from port_status */
flag = 0; flag = 0;
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment