Commit d4bdfcfb authored by Johan Hovold's avatar Johan Hovold Committed by Khalid Elmously

USB: legousbtower: fix slab info leak at probe

BugLink: https://bugs.launchpad.net/bugs/1848780

commit 1d427be4 upstream.

Make sure to check for short transfers when retrieving the version
information at probe to avoid leaking uninitialised slab data when
logging it.

Fixes: 1da177e4 ("Linux-2.6.12-rc2")
Cc: stable <stable@vger.kernel.org>
Signed-off-by: default avatarJohan Hovold <johan@kernel.org>
Link: https://lore.kernel.org/r/20190919083039.30898-2-johan@kernel.orgSigned-off-by: default avatarGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: default avatarConnor Kuehl <connor.kuehl@canonical.com>
Signed-off-by: default avatarKhalid Elmously <khalid.elmously@canonical.com>
parent 5f032184
...@@ -923,8 +923,10 @@ static int tower_probe (struct usb_interface *interface, const struct usb_device ...@@ -923,8 +923,10 @@ static int tower_probe (struct usb_interface *interface, const struct usb_device
get_version_reply, get_version_reply,
sizeof(*get_version_reply), sizeof(*get_version_reply),
1000); 1000);
if (result < 0) { if (result < sizeof(*get_version_reply)) {
dev_err(idev, "LEGO USB Tower get version control request failed\n"); if (result >= 0)
result = -EIO;
dev_err(idev, "get version request failed: %d\n", result);
retval = result; retval = result;
goto error; goto error;
} }
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment