mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Greg KH <gregkh@suse.de>
To: linux-kernel@vger.kernel.org, stable@kernel.org
Cc: stable-review@kernel.org, torvalds@linux-foundation.org,
	akpm@linux-foundation.org, alan@lxorguk.ukuu.org.uk,
	Bob Copeland <me@bobcopeland.com>,
	"John W. Linville" <linville@tuxdriver.com>
Subject: [patch 21/35] mac80211: fix minstrel single-rate memory corruption
Date: Tue, 30 Jun 2009 17:14:17 -0700	[thread overview]
Message-ID: <20090701001551.874389473@mini.kroah.org> (raw)
In-Reply-To: <20090701002825.GA6518@kroah.com>

[-- Attachment #1: mac80211-fix-minstrel-single-rate-memory-corruption.patch --]
[-- Type: text/plain, Size: 2076 bytes --]

2.6.29-stable review patch.  If anyone has any objections, please let us know.

------------------

From: Bob Copeland <me@bobcopeland.com>

commit 5ee58d7e6ad019675b4090582aec4fa1180d8703 upstream.

The minstrel rate controller periodically looks up rate indexes in
a sampling table.  When accessing a specific row and column, minstrel
correctly does a bounds check which, on the surface, appears to handle
the case where mi->n_rates < 2.  However, mi->sample_idx is actually
defined as an unsigned, so the right hand side is taken to be a huge
positive number when negative, and the check will always fail.

Consequently, the RC will overrun the array and cause random memory
corruption when communicating with a peer that has only a single rate.
The max value of mi->sample_idx is around 25 so casting to int should
have no ill effects.

Without the change, uptime is a few minutes under load with an AP
that has a single hard-coded rate, and both the AP and STA could
potentially crash.  With the change, both lasted 12 hours with a
steady load.

Thanks to Ognjen Maric for providing the single-rate clue so I could
reproduce this.

This fixes http://bugzilla.kernel.org/show_bug.cgi?id=12490 on the
regression list (also http://bugzilla.kernel.org/show_bug.cgi?id=13000).

Reported-by: Sergey S. Kostyliov <rathamahata@gmail.com>
Reported-by: Ognjen Maric <ognjen.maric@gmail.com>
Signed-off-by: Bob Copeland <me@bobcopeland.com>
Signed-off-by: John W. Linville <linville@tuxdriver.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>

---
 net/mac80211/rc80211_minstrel.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/net/mac80211/rc80211_minstrel.c
+++ b/net/mac80211/rc80211_minstrel.c
@@ -216,7 +216,7 @@ minstrel_get_next_sample(struct minstrel
 	unsigned int sample_ndx;
 	sample_ndx = SAMPLE_TBL(mi, mi->sample_idx, mi->sample_column);
 	mi->sample_idx++;
-	if (mi->sample_idx > (mi->n_rates - 2)) {
+	if ((int) mi->sample_idx > (mi->n_rates - 2)) {
 		mi->sample_idx = 0;
 		mi->sample_column++;
 		if (mi->sample_column >= SAMPLE_COLUMNS)



  parent reply	other threads:[~2009-07-01  0:43 UTC|newest]

Thread overview: 36+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <20090701001356.007288418@mini.kroah.org>
2009-07-01  0:28 ` [patch 00/35] 2.6.29-stable review Greg KH
2009-07-01  0:13   ` [patch 01/35] parport: netmos 9845 & 9855 1P4S fixes Greg KH
2009-07-01  0:13   ` [patch 02/35] 8250: Fix oops from setserial Greg KH
2009-07-01  0:13   ` [patch 03/35] char: mxser, fix ISA board lookup Greg KH
2009-07-01  0:14   ` [patch 04/35] jbd: fix race in buffer processing in commit code Greg KH
2009-07-01  0:14   ` [patch 05/35] r8169: fix crash when large packets are received Greg KH
2009-07-01  0:14   ` [patch 06/35] fs: remove incorrect I_NEW warnings Greg KH
2009-07-01  0:14   ` [patch 07/35] firmware_map: fix hang with x86/32bit Greg KH
2009-07-01  0:14   ` [patch 08/35] PCI: disable ASPM on VIA root-port-under-bridge configurations Greg KH
2009-07-01  0:14   ` [patch 09/35] atkbd: add forced release quirks for four more keyboard models Greg KH
2009-07-01  0:14   ` [patch 10/35] atmel_lcdfb: correct fifo size for some products Greg KH
2009-07-01  0:14   ` [patch 11/35] bonding: fix multiple module load problem Greg KH
2009-07-01  0:14   ` [patch 12/35] char: moxa, prevent opening unavailable ports Greg KH
2009-07-01  0:14   ` [patch 13/35] ISDN: Fix DMA alloc for hfcpci Greg KH
2009-07-01  0:14   ` [patch 14/35] USB: usbtmc: fix switch statment Greg KH
2009-07-01  0:14   ` [patch 15/35] x86: Add quirk for reboot stalls on a Dell Optiplex 360 Greg KH
2009-07-01  0:14   ` [patch 16/35] ALSA: ca0106 - Add missing registrations of vmaster controls Greg KH
2009-07-01  0:14   ` [patch 17/35] floppy: provide a PNP device table in the module Greg KH
2009-07-01  0:14   ` [patch 18/35] IB/mlx4: Add strong ordering to local inval and fast reg work requests Greg KH
2009-07-01  0:14   ` [patch 19/35] x86: handle initrd that extends into unusable memory Greg KH
2009-07-01  0:14   ` [patch 20/35] lockdep: Select frame pointers on x86 Greg KH
2009-07-01  0:14   ` Greg KH [this message]
2009-07-01  0:14   ` [patch 22/35] md/raid5: add missing call to schedule() after prepare_to_wait() Greg KH
2009-07-01  0:14   ` [patch 23/35] vt_ioctl: fix lock imbalance Greg KH
2009-07-01  0:14   ` [patch 24/35] x86: Set cpu_llc_id on AMD CPUs Greg KH
2009-07-01  0:14   ` [patch 25/35] parport_pc: after superio probing restore original register values Greg KH
2009-07-01  0:14   ` [patch 26/35] parport_pc: set properly the dma_mask for parport_pc device Greg KH
2009-07-01  0:14   ` [patch 27/35] PCI PM: Fix handling of devices without PM support by pci_target_state() Greg KH
2009-07-01  0:14   ` [patch 28/35] PCI PM: Follow PCI_PM_CTRL_NO_SOFT_RESET during transitions from D3 Greg KH
2009-07-01  0:14   ` [patch 29/35] pcmcia/cm4000: fix lock imbalance Greg KH
2009-07-01  0:14   ` [patch 30/35] qla2xxx: Correct (again) overflow during dump-processing on large-memory ISP23xx parts Greg KH
2009-07-01  0:14   ` [patch 31/35] sound: seq_midi_event: fix decoding of (N)RPN events Greg KH
2009-07-01  0:14   ` [patch 32/35] mm: fix handling of pagesets for downed cpus Greg KH
2009-07-01  0:14   ` [patch 33/35] dm mpath: validate table argument count Greg KH
2009-07-01  0:14   ` [patch 34/35] dm mpath: validate hw_handler " Greg KH
2009-07-01  0:14   ` [patch 35/35] dm: sysfs skip output when device is being destroyed Greg KH

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20090701001551.874389473@mini.kroah.org \
    --to=gregkh@suse.de \
    --cc=akpm@linux-foundation.org \
    --cc=alan@lxorguk.ukuu.org.uk \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linville@tuxdriver.com \
    --cc=me@bobcopeland.com \
    --cc=stable-review@kernel.org \
    --cc=stable@kernel.org \
    --cc=torvalds@linux-foundation.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

Powered by JetHome