mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Chris Wright <chrisw@sous-sol.org>
To: linux-kernel@vger.kernel.org, stable@kernel.org, torvalds@osdl.org
Cc: Justin Forbes <jmforbes@linuxtx.org>,
	Zwane Mwaikambo <zwane@arm.linux.org.uk>,
	"Theodore Ts'o" <tytso@mit.edu>,
	Randy Dunlap <rdunlap@xenotime.net>,
	Dave Jones <davej@redhat.com>,
	Chuck Wolber <chuckw@quantumlinux.com>,
	akpm@osdl.org, alan@lxorguk.ukuu.org.uk, tiwai@suse.de,
	greg@kroah.com, jk@blackdown.de, perex@suse.cz,
	Greg Kroah-Hartman <gregkh@suse.de>
Subject: [patch 21/39] [PATCH] Fix snd-usb-audio in 32-bit compat environment
Date: Mon, 27 Feb 2006 14:32:21 -0800	[thread overview]
Message-ID: <20060227223352.699835000@sorel.sous-sol.org> (raw)
In-Reply-To: <20060227223200.865548000@sorel.sous-sol.org>

[-- Attachment #1: fix-snd-usb-audio-in-32-bit-compat-environment.patch --]
[-- Type: text/plain, Size: 1740 bytes --]

-stable review patch.  If anyone has any objections, please let us know.
------------------

I'm getting oopses with snd-usb-audio in 32-bit compat environments:
control_compat.c:get_ctl_type() doesn't initialize 'info', so
'itemlist[uinfo->value.enumerated.item]' in
usbmixer.c:mixer_ctl_selector_info() might access random memory (The 'if
((int)uinfo->value.enumerated.item >= cval->max)' doesn't fix all problems
because of the unsigned -> signed conversion.)

Signed-off-by: Juergen Kreileder <jk@blackdown.de>
Cc: Jaroslav Kysela <perex@suse.cz>
Acked-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Andrew Morton <akpm@osdl.org>
Signed-off-by: Chris Wright <chrisw@sous-sol.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
---

 sound/core/control_compat.c |   16 +++++++++++-----
 1 files changed, 11 insertions(+), 5 deletions(-)

--- linux-2.6.15.4.orig/sound/core/control_compat.c
+++ linux-2.6.15.4/sound/core/control_compat.c
@@ -164,7 +164,7 @@ struct sndrv_ctl_elem_value32 {
 static int get_ctl_type(snd_card_t *card, snd_ctl_elem_id_t *id, int *countp)
 {
 	snd_kcontrol_t *kctl;
-	snd_ctl_elem_info_t info;
+	snd_ctl_elem_info_t *info;
 	int err;
 
 	down_read(&card->controls_rwsem);
@@ -173,13 +173,19 @@ static int get_ctl_type(snd_card_t *card
 		up_read(&card->controls_rwsem);
 		return -ENXIO;
 	}
-	info.id = *id;
-	err = kctl->info(kctl, &info);
+	info = kzalloc(sizeof(*info), GFP_KERNEL);
+	if (info == NULL) {
+		up_read(&card->controls_rwsem);
+		return -ENOMEM;
+	}
+	info->id = *id;
+	err = kctl->info(kctl, info);
 	up_read(&card->controls_rwsem);
 	if (err >= 0) {
-		err = info.type;
-		*countp = info.count;
+		err = info->type;
+		*countp = info->count;
 	}
+	kfree(info);
 	return err;
 }
 

--

  parent reply	other threads:[~2006-02-27 22:34 UTC|newest]

Thread overview: 49+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2006-02-27 22:32 [patch 00/39] Chris Wright
2006-02-27 22:32 ` [patch 01/39] ppc32: Put cache flush routines back into .relocate_code section Chris Wright
2006-02-27 22:32 ` [patch 02/39] [PATCH] s390: add #ifdef __KERNEL__ to asm-s390/setup.h Chris Wright
2006-02-27 22:32 ` [patch 03/39] shmdt cannot detach not-alined shm segment cleanly Chris Wright
2006-02-27 22:32 ` [patch 04/39] [PATCH] [BRIDGE]: netfilter missing symbol has_bridge_parent Chris Wright
2006-02-28  2:38   ` Horms
2006-02-27 22:32 ` [patch 05/39] [PATCH] i386: Move phys_proc_id/early intel workaround to correct function Chris Wright
2006-02-27 22:32 ` [patch 06/39] [PATCH] hugetlbfs mmap ENOMEM failure Chris Wright
2006-02-27 22:32 ` [patch 07/39] [PATCH] reiserfs: disable automatic enabling of reiserfs inode attributes Chris Wright
2006-02-27 22:32 ` [patch 08/39] [NET]: Revert skb_copy_datagram_iovec() recursion elimination Chris Wright
2006-02-27 22:32 ` [patch 09/39] [IPV6]: Address autoconfiguration does not work after device down/up cycle Chris Wright
2006-02-27 22:32 ` [patch 10/39] [PATCH] i386/x86-64: Dont IPI to offline cpus on shutdown Chris Wright
2006-02-27 22:37   ` Andi Kleen
2006-02-27 23:18     ` Chris Wright
2006-02-28  7:02       ` Eric W. Biederman
2006-03-01 22:19         ` Chris Wright
2006-02-27 22:32 ` [patch 11/39] [PATCH] sys_signal: initialize ->sa_mask Chris Wright
2006-02-27 22:32 ` [patch 12/39] [PATCH] do_sigaction: cleanup ->sa_mask manipulation Chris Wright
2006-02-27 22:32 ` [patch 13/39] [PATCH] [IA64] sys32_signal() forgets to initialize ->sa_mask Chris Wright
2006-02-27 22:32 ` [patch 14/39] [PATCH] Fix s390 build failure Chris Wright
2006-02-27 22:32 ` [patch 15/39] [PATCH] [BRIDGE]: Fix deadlock in br_stp_disable_bridge Chris Wright
2006-02-27 22:32 ` [patch 16/39] [PATCH] fix zap_threads ptrace related problems Chris Wright
2006-02-27 22:32 ` [patch 17/39] [PATCH] fix deadlock in ext2 Chris Wright
2006-02-27 22:32 ` [patch 18/39] [PATCH] sys_mbind sanity checking Chris Wright
2006-03-02  4:10   ` Dave Jones
2006-03-02  6:07     ` [stable] " Chris Wright
2006-02-27 22:32 ` [patch 19/39] [PATCH] it87: Fix oops on removal Chris Wright
2006-02-27 22:32 ` [patch 20/39] [PATCH] hwmon it87: Probe i2c 0x2d only Chris Wright
2006-02-27 22:32 ` Chris Wright [this message]
2006-02-27 22:32 ` [patch 22/39] [PATCH] alsa: fix bogus snd_device_free() in opl3-oss.c Chris Wright
2006-02-27 22:32 ` [patch 23/39] [PATCH] cfi: init wait queue in chip struct Chris Wright
2006-02-27 22:32 ` [patch 24/39] [PATCH] gbefb: Set default of FB_GBE_MEM to 4 MB Chris Wright
2006-02-27 22:32 ` [patch 25/39] [PATCH] dm: missing bdput/thaw_bdev at removal Chris Wright
2006-02-27 22:32 ` [patch 26/39] [PATCH] dm: free minor after unlink gendisk Chris Wright
2006-02-27 22:32 ` [patch 27/39] [PATCH] ramfs: update dir mtime and ctime Chris Wright
2006-02-27 22:32 ` [patch 28/39] [PATCH] gbefb: IP32 gbefb depth change fix Chris Wright
2006-02-27 22:32 ` [patch 29/39] [PATCH] skge: speed setting Chris Wright
2006-02-27 22:32 ` [patch 30/39] [PATCH] skge: fix NAPI/irq race Chris Wright
2006-02-27 22:32 ` [patch 31/39] [PATCH] skge: genesis phy initialization fix Chris Wright
2006-02-27 22:32 ` [patch 32/39] [PATCH] skge: fix SMP race Chris Wright
2006-02-27 22:32 ` [patch 33/39] [PATCH] x86_64: Check for bad elf entry address Chris Wright
2006-02-27 22:32 ` [patch 34/39] [NETLINK]: Fix a severe bug Chris Wright
2006-02-27 22:32 ` [patch 35/39] [PATCH] sd: fix memory corruption with broken mode page headers Chris Wright
2006-02-27 22:32 ` [patch 36/39] [PATCH] sbp2: fix another deadlock after disconnection Chris Wright
2006-02-27 22:32 ` [patch 37/39] [PATCH] XFS ftruncate() bug could expose stale data (CVE-2006-0554) Chris Wright
2006-02-27 22:32 ` [patch 38/39] Normal user can panic NFS client with direct I/O (CVE-2006-0555) Chris Wright
2006-03-02  4:33   ` Dave Jones
2006-03-02  7:25     ` [stable] " Chris Wright
2006-02-27 22:32 ` [patch 39/39] [PATCH] IB/mthca: max_inline_data handling tweaks Chris Wright

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20060227223352.699835000@sorel.sous-sol.org \
    --to=chrisw@sous-sol.org \
    --cc=akpm@osdl.org \
    --cc=alan@lxorguk.ukuu.org.uk \
    --cc=chuckw@quantumlinux.com \
    --cc=davej@redhat.com \
    --cc=greg@kroah.com \
    --cc=gregkh@suse.de \
    --cc=jk@blackdown.de \
    --cc=jmforbes@linuxtx.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=perex@suse.cz \
    --cc=rdunlap@xenotime.net \
    --cc=stable@kernel.org \
    --cc=tiwai@suse.de \
    --cc=torvalds@osdl.org \
    --cc=tytso@mit.edu \
    --cc=zwane@arm.linux.org.uk \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®