mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: alexander.levin@verizon.com
To: "linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>,
	"stable@vger.kernel.org" <stable@vger.kernel.org>
Cc: Bob Moore <robert.moore@intel.com>, Lv Zheng <lv.zheng@intel.com>,
	"Rafael J . Wysocki" <rafael.j.wysocki@intel.com>,
	alexander.levin@verizon.com
Subject: [PATCH AUTOSEL for 3.18 01/16] ACPICA: Resources: Not a valid resource if buffer length too long
Date: Wed, 15 Nov 2017 02:46:13 +0000	[thread overview]
Message-ID: <20171115024607.6064-1-alexander.levin@verizon.com> (raw)

From: Bob Moore <robert.moore@intel.com>

[ Upstream commit 57707a9a7780fab426b8ae9b4c7b65b912a748b3 ]

ACPICA commit 9f76de2d249b18804e35fb55d14b1c2604d627a1
ACPICA commit b2e89d72ef1e9deefd63c3fd1dee90f893575b3a
ACPICA commit 23b5bbe6d78afd3c5abf3adb91a1b098a3000b2e

The declared buffer length must be the same as the length of the
byte initializer list, otherwise not a valid resource descriptor.

Link: https://github.com/acpica/acpica/commit/9f76de2d
Link: https://github.com/acpica/acpica/commit/b2e89d72
Link: https://github.com/acpica/acpica/commit/23b5bbe6
Signed-off-by: Bob Moore <robert.moore@intel.com>
Signed-off-by: Lv Zheng <lv.zheng@intel.com>
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Sasha Levin <alexander.levin@verizon.com>
---
 drivers/acpi/acpica/utresrc.c | 17 ++++++++++++-----
 1 file changed, 12 insertions(+), 5 deletions(-)

diff --git a/drivers/acpi/acpica/utresrc.c b/drivers/acpi/acpica/utresrc.c
index 5cd017c7ac0e..94b3ee013761 100644
--- a/drivers/acpi/acpica/utresrc.c
+++ b/drivers/acpi/acpica/utresrc.c
@@ -421,8 +421,10 @@ acpi_ut_walk_aml_resources(struct acpi_walk_state *walk_state,
 
 	ACPI_FUNCTION_TRACE(ut_walk_aml_resources);
 
-	/* The absolute minimum resource template is one end_tag descriptor */
-
+	/*
+	 * The absolute minimum resource template is one end_tag descriptor.
+	 * However, we will treat a lone end_tag as just a simple buffer.
+	 */
 	if (aml_length < sizeof(struct aml_resource_end_tag)) {
 		return_ACPI_STATUS(AE_AML_NO_RESOURCE_END_TAG);
 	}
@@ -454,9 +456,8 @@ acpi_ut_walk_aml_resources(struct acpi_walk_state *walk_state,
 		/* Invoke the user function */
 
 		if (user_function) {
-			status =
-			    user_function(aml, length, offset, resource_index,
-					  context);
+			status = user_function(aml, length, offset,
+					       resource_index, context);
 			if (ACPI_FAILURE(status)) {
 				return_ACPI_STATUS(status);
 			}
@@ -480,6 +481,12 @@ acpi_ut_walk_aml_resources(struct acpi_walk_state *walk_state,
 				*context = aml;
 			}
 
+			/* Check if buffer is defined to be longer than the resource length */
+
+			if (aml_length > (offset + length)) {
+				return_ACPI_STATUS(AE_AML_NO_RESOURCE_END_TAG);
+			}
+
 			/* Normal exit */
 
 			return_ACPI_STATUS(AE_OK);
-- 
2.11.0

             reply	other threads:[~2017-11-15  2:58 UTC|newest]

Thread overview: 16+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2017-11-15  2:46 alexander.levin [this message]
2017-11-15  2:46 ` [PATCH AUTOSEL for 3.18 03/16] PCI: Apply _HPX settings only to relevant devices alexander.levin
2017-11-15  2:46 ` [PATCH AUTOSEL for 3.18 02/16] RDS: RDMA: return appropriate error on rdma map failures alexander.levin
2017-11-15  2:46 ` [PATCH AUTOSEL for 3.18 05/16] net: 3com: typhoon: typhoon_init_one: fix incorrect return values alexander.levin
2017-11-15  2:46 ` [PATCH AUTOSEL for 3.18 04/16] net: 3com: typhoon: typhoon_init_one: make return values more specific alexander.levin
2017-11-15  2:46 ` [PATCH AUTOSEL for 3.18 06/16] drm/armada: Fix compile fail alexander.levin
2017-11-15  2:46 ` [PATCH AUTOSEL for 3.18 07/16] ALSA: hda - Apply ALC269_FIXUP_NO_SHUTUP on HDA_FIXUP_ACT_PROBE alexander.levin
2017-11-15  2:46 ` [PATCH AUTOSEL for 3.18 11/16] netfilter: nft_queue: use raw_smp_processor_id() alexander.levin
2017-11-15  2:46 ` [PATCH AUTOSEL for 3.18 09/16] mac80211: Suppress NEW_PEER_CANDIDATE event if no room alexander.levin
2017-11-15  2:46 ` [PATCH AUTOSEL for 3.18 12/16] netfilter: nf_tables: fix oob access alexander.levin
2017-11-15  2:46 ` [PATCH AUTOSEL for 3.18 08/16] mac80211: Remove invalid flag operations in mesh TSF synchronization alexander.levin
2017-11-15  2:46 ` [PATCH AUTOSEL for 3.18 10/16] staging: iio: cdc: fix improper return value alexander.levin
2017-11-15  2:46 ` [PATCH AUTOSEL for 3.18 15/16] s390/kbuild: enable modversions for symbols exported from asm alexander.levin
2017-11-15  2:46 ` [PATCH AUTOSEL for 3.18 14/16] ASoC: wm_adsp: Don't overrun firmware file buffer when reading region data alexander.levin
2017-11-15  2:46 ` [PATCH AUTOSEL for 3.18 13/16] btrfs: return the actual error value from from btrfs_uuid_tree_iterate alexander.levin
2017-11-15  2:46 ` [PATCH AUTOSEL for 3.18 16/16] xen: xenbus driver must not accept invalid transaction ids alexander.levin

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20171115024607.6064-1-alexander.levin@verizon.com \
    --to=alexander.levin@verizon.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=lv.zheng@intel.com \
    --cc=rafael.j.wysocki@intel.com \
    --cc=robert.moore@intel.com \
    --cc=stable@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®