Commit Graph
345545 Commits
Author SHA1 Message Date
Hu Wang 859cb988e7 wlan: Clear the bits in Ext Cap IE if AP not support
Some specific AP will send assoc reject if DUT set the bits of
Ext Cap IE which AP not advertise in beacon or probe response.
To avoid the IoT issue, clear the bits in Ext Cap IE if AP not
support.

Change-Id: I632f5474331abf51257cacdcce412d7a110d2433
CRs-Fixed: 1052140
2020-05-21 10:54:45 +02:00
Hu Wang 0409e22658 wlan: Use variable length for Ext Cap IE
Ext Cap IE is defined as fixed length in driver. But some
AP sends beacon or probe resp with variable length of
Ext Cap IE, then dot11f will decode it to invalid value.

To fix this, use variable length for Ext Cap IE.

Change-Id: I910edfddf3ea64bc3000b6e7803dc57a50399dbb
CRs-Fixed: 1052140
2020-05-21 10:54:44 +02:00
Gupta, Kapil d4c2d6a92d Wlan: Correct ext IE in Assoc req
qcacld-2.0 to prima propagation

Add the changes to add ext IEs in assoc req based on extended IEs
host is getting from framework.

CRs-Fixed: 977188
Change-Id: Idacfa287d17a2409f054421229d04ff087aa28d8
2020-05-21 10:54:44 +02:00
Abhishek Singh ef024cdb5f Wlan: Merge ext cap from supplicant if bssTransition bit is set
Ext cap from supplicant is taken in consideration while sending assoc
request only if internetworking bit is set and thus if the
internetworking bit is not set in the ext cap from supplicant it is
not merged with ext cap of the assoc req.

Thus bssTransition bit info in ext cap provided by supplicant is
not taken in consideration if internetworking bit is not set.

To fix this merge the ext cap from supplicant if internetworking
or bssTransition bits are set.

Change-Id: I81d5d8c417dd7adc75b9864b625a00d53657df6c
CRs-Fixed: 964383
2020-05-21 10:54:43 +02:00
Padma, Santhosh Kumar c8d3067f78 wlan: Avoid buffer overflow
qcacld-2.0 to prima propagation

Add max check for probe request length against max length of probe
request buffer to avoid buffer overflow.

Change-Id: Ie0fad7443b2c749c66bb9ad662625a16d3a840c3
CRs-Fixed: 2184098
2020-05-21 10:54:42 +02:00
Abhinav Kumar 97b9687c83 wlan: Fix potential OOB read in dot11f.c
In function get_container_ies_len, nBuf is passed from caller function
as length of the buffer remaining in the frame. len is calculated from
the length field present in the IE. Then find_ie_defn is called with
nBuf + len as buffer length available leading to potential OOB read
in the function find_ie_defn.
Also in function get_container_ies_len, if len is greater than nBuf,
OOB read would occur in the caller function unpack_core.

In function unpack_core, len is calculated from the length field in
the IE buffer, then the IE is parsed in one of the unpack functions
where len is decremented without any check for min value of len.
If the value of len obtained from the IE buffer is less than the
minSize of the IE, then an integer underflow would occur.
1. In function get_container_ies_len, change calling of find_ie_defn
to use nbuf - len.
2. In function get_container_ies_len, if len > nbuf, return error.
3. In function unpack_core, add sanity check to make sure len is not
less thatn IE's minSize.

Change-Id: I8e42fb7e9674845d152d2ec26a592e02a1b562ab
CRs-Fixed: 2164275
2020-05-21 10:54:42 +02:00
Vignesh Viswanathan 7d3e1ba99c wlan: Fix buffer overrun in function ProcSetReqInternal
In function ProcSetReqInternal, valueLen is obtained from the
message buffer pParam. This valueLen is used as argument to the
function GetStrValue where the contents of the buffer pParam is
copied to pMac->cfg.gSBuffer for valueLen number of bytes. However
the array pMac->cfg.gSBuffer is a static array of size CFG_MAX_STR_LEN.
If the value of valueLen exceeds CFG_MAX_STR_LEN, a buffer overwrite
will occur in GetStrValue.

Add Sanity check to make sure valueLen does not exceed CFG_MAX_STR_LEN.

Change-Id: Id16d4c4b8d2414c00a0fae8f8292f011d0763b84
CRs-Fixed: 2158080
2020-05-21 10:54:41 +02:00
Vignesh Viswanathan 09edd8afac wlan: Add sanity check to limit mgmt frames data len
Currently the frameLen in Rx pkt meta is not checked for
upper bound in peHandleMgmtFrame.

Add sanity check to drop the packet if frameLen is
greater than 2000 bytes. Also add upper bound check for
frameLen in limProcessAuthFrame function.

Change-Id: Id8d80f892c18d044896224c22b21f667ee30eb6b
CRs-Fixed: 2146331
2020-05-21 10:54:19 +02:00
yeshwanth sriram guntuka 62fbd622f0 wlan: Set length of challenge text sent by SAP to 128
SIR_MAC_AUTH_CHALLENGE_LENGTH is updated to 253 from
128 as per IEEE spec due to connection fails between
DUT-SAP and old ref-STA. Auth failure occurs as encrypted
data sent by ref-STA is only 128 bytes instead of 253
bytes.

Fix is to set length of challenge text sent by SAP
to 128 bytes.

Change-Id: I81409bb58ad34e469c54e2909f45b8a6826eb06a
CRs-Fixed: 2096512
2020-05-21 10:54:19 +02:00
Sravan Kumar Kairam b98c18a899 wlan: Fix reorder packets PN replay check algorithm
Currently for reorder packets PN replay check of the out
of order missing packet is done with the last packet received
in the reorder window slot. The PN number of the out of order
missing packet will be less than the last received packet in
the window and packet drop happens because of replay check.

In this change fix the logic by doing the replay check of the
out of order missing packet with the previous sequence packet
that of out of order packet.

Change-Id: Ib83b825d4b9b292e125c98d819fdfa6eb160e389
CRs-Fixed: 2145435
2020-05-21 10:54:18 +02:00
Sravan Kumar Kairam d90a26e2f7 wlan: Retrieve sta id for only PTK key
Currently at add key mac address is NULL for GTK key. So while
retrieving sta id system crashes as address is NULL. In this
change check if pairwise key and then only retrieve sta id from
mac.

Change-Id: I2f2f6e0e10cdc6eabd78ff2dc5108969403d9a27
CRs-Fixed: 2141572
2020-05-21 10:54:17 +02:00
Sravan Kumar Kairam b7e591d1bd wlan: Update key sequence counter to TL
Currently the key sequence counter received from user space is
not updated at TL. So update the sequence counter to TL.

Change-Id: I460d64511502fd414d0e8568c69712bbe54dd7fa
CRs-Fixed: 2136293
2020-05-21 10:54:16 +02:00
Nachiket Kukade e0bd099d1a wlan: Add maximum bound check on WPA RSN IE length
WPA RSN IE is copied from source without a check on the given IE length.
A malicious IE length can cause buffer overflow.
Add maximum bound check on WPA RSN IE length.

Change-Id: Id159d307e8f9c1de720d4553a7c29f23cbd28571
CRs-Fixed: 2058978
2020-05-21 10:54:16 +02:00
Nachiket Kukade 2ed2afd83f wlan: Check on IE length to avoid buffer over-read
An incorrect IE length can overflow the remaining length variable
and make IE parsing logic perform a buffer over-read.
Check on IE length to avoid buffer over-read.

Change-Id: I20ef6a0136c7a5b602ad15a2fb725f20807b81d0
CRs-Fixed: 2058954
2020-05-21 10:54:15 +02:00
Nishank Aggarwal 04ae070b72 wlan: Add check for set_ft_ies buffer length
qcacld-3.0 to prima propagation

Add check for buffer length in function sme_set_ft_ies.

Change-Id: I7adc56e23316c0ceb193a5bdf8c4c0b5f4fbd20a
CRs-Fixed: 2055659
2020-05-21 10:54:14 +02:00
SaidiReddy Yenuga 796f116067 wlan: Fix buffer overread in get oui vendor command
qcacld-2.0 to Prima Propagation.

In get oui ie command API, ie pointer read out
of boundary.

Return NULL if ie length is less than oui size.

CRs-Fixed: 2053006
Change-Id: I13375d3bfa472eda25d8d6191431dd1f79bf5842
2020-05-21 10:54:14 +02:00
Vignesh Viswanathan 7f42d22450 wlan: Fix out-of-bounds access in limProcessActionFrameNoSession
Currently in the function limProcessActionFrameNoSession, mem_cmp
is done on the received frame pointer without validating the frame_len
which could lead to out-of-bounds memory access if the frame_len is
not matching the size of action_hdr.

Add check to validate the frame_len with action_hdr size before doing
mem_cmp for the p2p oui.

Change-Id: I39329d1a9ef45614d3c617db11a7a7f5ec2aaaec
CRs-Fixed: 2110756
2020-05-21 10:54:13 +02:00
Sridhar Selvaraj 411dee9d46 wlan: Fix incorrect processing of encrypted auth frame
qcacld-3.0 to prima propagation.

Fix incorrect processing of encrypted auth frame by allocating
appropriate local buffer and using correct type for frame length.

Change-Id: I87d6f4c3c43dd332d5b1877ddf4b3b46a717468b
CRs-Fixed: 2083572
2020-05-21 10:54:12 +02:00
Sridhar Selvaraj 4b0a8cb3f2 wlan: Change local variables to dynamic in limProcessAuthFrame
Currently limProcessAuthFrame stack frame size exceeds 1024 and causes
build failures for 32 bit platforms.

Move multiple variables from local to dynamic allocation to reduce the
frame size of limProcessAuthFrame.

Change-Id: I83cf5ab24693e0ce012894d808ac79bf37fa9a08
CRs-Fixed: 2083572
2020-05-21 10:54:12 +02:00
Sridhar Selvaraj 4d60eeeec3 wlan: Update SIR_MAC_AUTH_CHALLENGE_LENGTH as per IEEE spec
qcacld-3.0 to prima propagation

Update SIR_MAC_AUTH_CHALLENGE_LENGTH to 253 as per IEEE spec.
Currently value of SIR_MAC_AUTH_CHALLENGE_LENGTH is set to 128.
This may result in potential buffer overflow since frame parser
allows challenge text of length upto 253 but driver can not handle
challenge text longer than 128 bytes.

Change-Id: I7baf860fdde51a14a6573b4f0f26817f5071193e
CRs-Fixed: 2076603
2020-05-21 10:54:11 +02:00
Sridhar Selvaraj 3c7a0d2d78 wlan: Update limComputeCrc32 to pass uint16_t
qcacld-3.0 to prima propagation

Update limComputeCrc32() to pass uint16_t as a length type.
Currently uint8_t is being passed as length and there will be type
mismatch when authentication frame to be encrypted will be larger
than 255 bytes.

Change-Id: Ic009197c13a2d70c9015a184acff2e82bf80eaba
CRs-Fixed: 2076603
2020-05-21 10:54:10 +02:00
Sridhar Selvaraj f76570ef72 wlan: Remove warning logs in beacon/probe response parsing
Currently, parsing of beacon/probe response leads to flooding of
warning messages in kernel logs.

Remove warning logs in beacon/probe response parsing. Dump IE's
only for parse fail case as debug logs.

Change-Id: I1b6898377cc196a5c4fe3d3316618104fd8b281e
CRs-Fixed: 2074411
2020-05-21 10:54:10 +02:00
Sridhar Selvaraj 34bc594c93 wlan: Add bound check before writing to channel list
In function rrmProcessBeaconReportReq, add bound check before
writing to channel list which is of fixed size.

Change-Id: I3c80974bba84a96f7b85e4ce62bbb01c23b4babf
CRs-Fixed: 2072774
2020-05-21 10:54:09 +02:00
Rajeev Kumar Sirasanagandla 72a1ee8cee wlan: Avoid concurrent matrix max param overread
qcacld-3.0 to prima propagation.

Currently there is no nl policy defined for vendor sub command
QCA_NL80211_VENDOR_SUBCMD_GET_CONCURRENCY_MATRIX which may result in
buffer overread error.

To resolve this, add nl policy.

Change-Id: I155efdbb07f1c5fe300bb2be0c2a3fe07c7e134b
CRs-Fixed: 2058455
2020-05-21 10:54:08 +02:00
Sridhar Selvaraj b93a507b55 prima: Skip an IE if found more its max times in a frame
Check if a IE has been encountered more than max possible for that IE
while parsing a frame.

Change-Id: I1054c7df18780469849be55fc4343f09ac502a49
CRs-Fixed: 2069927
2020-05-21 10:54:08 +02:00
Kapil Gupta 04ee1dfdee wlan: Drop assoc request if RSNIE/WPAIE parsing fail
Add changes to drop assoc request and return error if RSNIE or
WPAIE parsing fail during parsing of assoc request.

CRs-Fixed: 2056775
Change-Id: I88d779399c2eba5d33c30144bf9600a1f3a00b77
2020-05-21 10:54:07 +02:00
Sen, Devendra 2ffd077e95 wlan: Validate BA tid before accessing
Add changes to validate BA tid in delBA params before accessing
it.

CRs-Fixed: 2044049
Change-Id: I6e98189ccd1710d9928bc1f585061bd9ff414c49
2020-05-21 10:54:06 +02:00
Sreelakshmi Konamki 0aa309753d wlan: Remove PTK/GTK debug logs
Currently host prints PTK and GTK key information in default logs.
Fix to remove the debug logs which prints sensitive key information.

Change-Id: I358b09b77d23eeb5da7d826859ae119a8ea4af8a
CRs-Fixed: 1097857
2020-05-21 10:54:06 +02:00
Sachin Ahuja c16c636698 prima: Validate station id
In function hdd_hostapd_select_queue, station id is not validated with
max station count, this might lead to a buffer overflow situation for array
aStaInfo in SapCtx.
Validate station id with max sta count.

Change-Id: Ic1dd825b6437e4b0d7d8ed133184674bbfa53699
CRs-Fixed: 1092611
2020-05-21 10:54:04 +02:00
Sachin Ahuja 90996a04c7 prima: Validate pkt buffer size.
In function parse_Bufferforpkt, pkt data index is not validated.
This may lead to a buffer overflow if the incoming buffer is too large.

Validate packet buffer length with the total allowed pkt buffer size.

Change-Id: I9b9ffa592cbe3a0d87af3cbbef3608bc59e01cfc
CRs-Fixed: 1092599
2020-05-21 10:53:53 +02:00
Hanumanth Reddy Pothula 295030a4c5 wlan: Return updated rssi value to upperlayer
On rssi request from wext interface, get updated rssi value from
firmware. So that host can send updated rssi to upper layer,
instead of stale value

Change-Id: I8443fbdc9ace1f15caf2df22c1b337eaf54823ac
CRs-Fixed: 1033997
2020-05-21 10:53:46 +02:00
SaidiReddy Yenuga 27993aa635 wlan: Add get valid channels entry to NLA policy
qcacld-2.0 to prima Propagation.

improper validation of
QCA_WLAN_VENDOR_ATTR_EXTSCAN_GET_VALID_CHANNELS_CONFIG_PARAM_MAX_CHANNELS.

validate QCA_WLAN_VENDOR_ATTR_EXTSCAN_GET_VALID_CHANNELS_CONFIG_PARAM_MAX_CHANNELS.

Bug: 36817053
Issue: SEC-595
CRs-Fixed: 2052990
Change-Id: I16e5808492b5b35dc8b646af45d6ac6d65561804
(cherry picked from commit 02f0807dc4d15c93b8d8f8cb8204fdcc12193482)
2020-05-21 10:53:39 +02:00
Ratnam Rachuri d0e4e90960 wlan: Avoid releasing mutex for un-acquired tdls lock
Trying to release the mutex which was not acquired in
wlan_hdd_tdls_disconnection_callback fn. So removing
mutex_unlock(&pHddCtx->tdls_lock) to resolve the issue.

Change-Id: I2fe402370e6623d4465f14e072a8fad23775d348
CRs-Fixed: 941576
2020-05-21 10:52:01 +02:00
prototype74 10e8255936 msm_otg: compile otg as module platform driver
Also includes patches from official v3.10.x sources

Change-Id: I5adb63888b613ef74dda15cdf17c62e8f98cf685
2020-05-20 15:02:09 +02:00
prototype74 c1e0e733a7 mdss: improved video_pingpong (s6e8aa0a) + general mdss improvements
Proper implemented video_pingpong and video_wait4pingpong which caused framerate drops on s6e8aa0a panels at low tasks. Further additional general improvements and fixes from official samsung msm8916 sources.

Change-Id: I9e15962162ca2ca52bb5832593e6b368eea80db2
2020-05-20 15:01:51 +02:00
prototype74 7d8a76fece sm5502: auto enable/disable 8226_smbbp_otg regulator
Automatically enable/disable 8226_smbbp_otg regulator for kmini3g, s3ve3g to supply connected OTG devices from device's power instead of external power source.

Based on https://github.com/Pavlex4/S3-Neo-Kernel/commit/4f03ed4b33abcf3c0b8277ab9718adefbe4fb874

Change-Id: Ibd2b3fb6417faf630ed13985c26ee45400e88674
2020-05-20 15:00:46 +02:00
Sumalatha Malothu f8ae162dec msm: camera_v2: handle the error value returned during get clock
currently only NULL pointer check is used to validate the return
value from clk_get, this change to handle all the failures.
This snapshot is taken from msm-4.9
Ported it from 4.9 to 3.18

Change-Id: Icd8b7e33d0f235a7c5dde2307972a594908e6a60
Signed-off-by: Sumalatha Malothu <smalot@codeaurora.org>
[haggertk: Backport to 3.4/msm8974. Note that this includes patching
 the non-standard camera_ll implementation as well on this kernel.]
CVE-2019-10524
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2020-05-20 09:45:31 +02:00
Zhen Kong 470ff23716 qseecom: check invalid handle for app loaded query request
Check if the handle data type received from userspace is valid
for app loaded query request to avoid the offset boundary check
for qseecom_send_modfd_resp is bypassed.

Bug: 143972932
Change-Id: I5f3611a8f830d6904213781c5ba70cfc0ba3e2e0
Signed-off-by: Zhen Kong <zkong@codeaurora.org>
CVE-2019-14041
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2020-05-20 09:44:44 +02:00
jitendrathakare b2e0d99b7b qseecom : Clear client handle after unmap the resources
When unloading the app, reset all client members to NULL
to protect from accessing the memory after being freed.

Bug: 143973884
Change-Id: I573b9c6fde03539522d2b04724a2246660c62518
Signed-off-by: jitendra thakare <jitendrathakare@codeaurora.org>
CVE-2019-14040
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2020-05-20 09:44:43 +02:00
Alan Stern 30ed47965b HID: Fix assumption that devices have inputs
commit d9d4b1e46d9543a82c23f6df03f4ad697dab361b upstream.

The syzbot fuzzer found a slab-out-of-bounds write bug in the hid-gaff
driver.  The problem is caused by the driver's assumption that the
device must have an input report.  While this will be true for all
normal HID input devices, a suitably malicious device can violate the
assumption.

The same assumption is present in over a dozen other HID drivers.
This patch fixes them by checking that the list of hid_inputs for the
hid_device is nonempty before allowing it to be used.

Reported-and-tested-by: syzbot+403741a091bf41d4ae79@syzkaller.appspotmail.com
Signed-off-by: Alan Stern <stern@rowland.harvard.edu>
Signed-off-by: Benjamin Tissoires <benjamin.tissoires@redhat.com>
[bwh: Backported to 3.16:
 - Drop changes in hid-logitech-hidpp, hid-microsoft
 - Adjust context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
[haggertk: Backported to android/3.4:
 - Drop changes to hid-sony, add changes to hid-pidff]
CVE-2019-19532
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
Change-Id: Icfe325236f0c40aa0c3ca638e903179b3935ad1e
2020-05-20 09:44:43 +02:00
Oliver Neukum e95c2c768b Input: ff-memless - kill timer in destroy()
commit fa3a5a1880c91bb92594ad42dfe9eedad7996b86 upstream.

No timer must be left running when the device goes away.

Signed-off-by: Oliver Neukum <oneukum@suse.com>
Reported-and-tested-by: syzbot+b6c55daa701fc389e286@syzkaller.appspotmail.com
Link: https://lore.kernel.org/r/1573726121.17351.3.camel@suse.com
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
CVE-2019-19524
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
Change-Id: I98f48deb9af84d551faffa98138384bc5db9ac61
2020-05-20 09:44:33 +02:00
Grant Hernandez e23d52b6b6 Input: gtco - bounds check collection indent level
commit 2a017fd82c5402b3c8df5e3d6e5165d9e6147dc1 upstream.

The GTCO tablet input driver configures itself from an HID report sent
via USB during the initial enumeration process. Some debugging messages
are generated during the parsing. A debugging message indentation
counter is not bounds checked, leading to the ability for a specially
crafted HID report to cause '-' and null bytes be written past the end
of the indentation array. As long as the kernel has CONFIG_DYNAMIC_DEBUG
enabled, this code will not be optimized out.  This was discovered
during code review after a previous syzkaller bug was found in this
driver.

Signed-off-by: Grant Hernandez <granthernandez@google.com>
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
CVE-2019-13631
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
Change-Id: I0c205755470fa7b9cc83d8b80263c535c272eb18
2020-05-20 09:44:23 +02:00
Matt Delco 7477bbe30c KVM: coalesced_mmio: add bounds checking
commit b60fe990c6b07ef6d4df67bc0530c7c90a62623a upstream.

The first/last indexes are typically shared with a user app.
The app can change the 'last' index that the kernel uses
to store the next result.  This change sanity checks the index
before using it for writing to a potentially arbitrary address.

This fixes CVE-2019-14821.

Fixes: 5f94c1741b ("KVM: Add coalesced MMIO support (common part)")
Signed-off-by: Matt Delco <delco@chromium.org>
Signed-off-by: Jim Mattson <jmattson@google.com>
Reported-by: syzbot+983c866c3dd6efa3662a@syzkaller.appspotmail.com
[Use READ_ONCE. - Paolo]
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
[bwh: Backported to 3.16:
 - Use ACCESS_ONCE() instead of READ_ONCE()
 - kvm_coalesced_mmio_zone::pio field is not supported]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
Change-Id: I9e34e14d695dc507757fa215407f0b7ac9445e2b
2020-05-20 09:44:23 +02:00
Denis Efremov f6b7a635a0 floppy: fix out-of-bounds read in copy_buffer
commit da99466ac243f15fbba65bd261bfc75ffa1532b6 upstream.

This fixes a global out-of-bounds read access in the copy_buffer
function of the floppy driver.

The FDDEFPRM ioctl allows one to set the geometry of a disk.  The sect
and head fields (unsigned int) of the floppy_drive structure are used to
compute the max_sector (int) in the make_raw_rw_request function.  It is
possible to overflow the max_sector.  Next, max_sector is passed to the
copy_buffer function and used in one of the memcpy calls.

An unprivileged user could trigger the bug if the device is accessible,
but requires a floppy disk to be inserted.

The patch adds the check for the .sect * .head multiplication for not
overflowing in the set_geometry function.

The bug was found by syzkaller.

Signed-off-by: Denis Efremov <efremov@ispras.ru>
Tested-by: Willy Tarreau <w@1wt.eu>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
CVE-2019-14283
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
Change-Id: Idb3e900d17920e6339b862419018f4740a7d4caf
2020-05-20 09:44:22 +02:00
Oliver Neukum d8b1386e6b media: dvb: usb: fix use after free in dvb_usb_device_exit
[ Upstream commit 6cf97230cd5f36b7665099083272595c55d72be7 ]

dvb_usb_device_exit() frees and uses the device name in that order.
Fix by storing the name in a buffer before freeing it.

Signed-off-by: Oliver Neukum <oneukum@suse.com>
Reported-by: syzbot+26ec41e9f788b3eba396@syzkaller.appspotmail.com
Signed-off-by: Sean Young <sean@mess.org>
Signed-off-by: Mauro Carvalho Chehab <mchehab+samsung@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
CVE-2019-15213
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
Change-Id: Ia218933795b4847765450522202d1b67e326c3cd
2020-05-20 09:44:22 +02:00
Oliver Neukum 45455d5646 USB: rio500: refuse more than one device at a time
commit 3864d33943b4a76c6e64616280e98d2410b1190f upstream.

This driver is using a global variable. It cannot handle more than
one device at a time. The issue has been existing since the dawn
of the driver.

Signed-off-by: Oliver Neukum <oneukum@suse.com>
Reported-by: syzbot+35f04d136fc975a70da4@syzkaller.appspotmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
CVE-2019-15212
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
Change-Id: I96bac47f327839f08944cb047f20e328ed8e3473
2020-05-20 09:44:22 +02:00
Dan Carpenter 50cd1f1db2 ath6kl: add some bounds checking
commit 5d6751eaff672ea77642e74e92e6c0ac7f9709ab upstream.

The "ev->traffic_class" and "reply->ac" variables come from the network
and they're used as an offset into the wmi->stream_exist_for_ac[] array.
Those variables are u8 so they can be 0-255 but the stream_exist_for_ac[]
array only has WMM_NUM_AC (4) elements.  We need to add a couple bounds
checks to prevent array overflows.

I also modified one existing check from "if (traffic_class > 3) {" to
"if (traffic_class >= WMM_NUM_AC) {" just to make them all consistent.

Fixes: bdcd817079 (" Add ath6kl cleaned up driver")
Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
Signed-off-by: Kalle Valo <kvalo@codeaurora.org>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
CVE-2019-15926
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
Change-Id: I0bcdbfb3acdbabfe4bc232431a91405155f34771
2020-05-20 09:44:21 +02:00
Sean Young b369af9c3a media: technisat-usb2: break out of loop at end of buffer
commit 0c4df39e504bf925ab666132ac3c98d6cbbe380b upstream.

Ensure we do not access the buffer beyond the end if no 0xff byte
is encountered.

Reported-by: syzbot+eaaaf38a95427be88f4b@syzkaller.appspotmail.com
Signed-off-by: Sean Young <sean@mess.org>
Reviewed-by: Kees Cook <keescook@chromium.org>
Signed-off-by: Mauro Carvalho Chehab <mchehab+samsung@kernel.org>
[bwh: Backported to 3.16: technisat_usb2_get_ir() still uses a stack
 buffer, which is not worth fixing on this branch]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
CVE-2019-15505
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
Change-Id: I9561df3437dec3d0bd2770c1f831d68bb26a9a6e
2020-05-20 09:44:21 +02:00
Hui Peng 199667e7dd ALSA: usb-audio: Fix an OOB bug in parse_audio_mixer_unit
commit daac07156b330b18eb5071aec4b3ddca1c377f2c upstream.

The `uac_mixer_unit_descriptor` shown as below is read from the
device side. In `parse_audio_mixer_unit`, `baSourceID` field is
accessed from index 0 to `bNrInPins` - 1, the current implementation
assumes that descriptor is always valid (the length  of descriptor
is no shorter than 5 + `bNrInPins`). If a descriptor read from
the device side is invalid, it may trigger out-of-bound memory
access.

```
struct uac_mixer_unit_descriptor {
	__u8 bLength;
	__u8 bDescriptorType;
	__u8 bDescriptorSubtype;
	__u8 bUnitID;
	__u8 bNrInPins;
	__u8 baSourceID[];
}
```

This patch fixes the bug by add a sanity check on the length of
the descriptor.

Reported-by: Hui Peng <benquike@gmail.com>
Reported-by: Mathias Payer <mathias.payer@nebelwelt.net>
Signed-off-by: Hui Peng <benquike@gmail.com>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
CVE-2019-15117
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
Change-Id: I4173c102a7f0752d8113823f5070ccb7de5f8914
2020-05-20 09:44:21 +02:00
Eric Dumazet a7bf23e722 inet: switch IP ID generator to siphash
commit df453700e8d81b1bdafdf684365ee2b9431fb702 upstream.

According to Amit Klein and Benny Pinkas, IP ID generation is too weak
and might be used by attackers.

Even with recent net_hash_mix() fix (netns: provide pure entropy for net_hash_mix())
having 64bit key and Jenkins hash is risky.

It is time to switch to siphash and its 128bit keys.

Signed-off-by: Eric Dumazet <edumazet@google.com>
Reported-by: Amit Klein <aksecurity@gmail.com>
Reported-by: Benny Pinkas <benny@pinkas.net>
Signed-off-by: David S. Miller <davem@davemloft.net>
[bwh: Backported to 3.16: adjust context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
CVE-2019-10638
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
Change-Id: I607618745f8725e7318ec60e470a77bf0e53df8b
2020-05-20 09:44:20 +02:00