From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1752650Ab0BGIZ2 (ORCPT ); Sun, 7 Feb 2010 03:25:28 -0500 Received: from cantor2.suse.de ([195.135.220.15]:45396 "EHLO mx2.suse.de" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1752125Ab0BGIZ1 (ORCPT ); Sun, 7 Feb 2010 03:25:27 -0500 Date: Sun, 07 Feb 2010 09:25:26 +0100 Message-ID: From: Takashi Iwai To: "Jody@Tritech" Cc: linux-kernel@vger.kernel.org Subject: Re: [PATCH] hda-intel: Avoid divide by zero crash In-Reply-To: <4B6D8ED2.5060107@nctritech.com> References: <4B6D8ED2.5060107@nctritech.com> User-Agent: Wanderlust/2.15.6 (Almost Unreal) SEMI/1.14.6 (Maruoka) FLIM/1.14.9 (=?UTF-8?B?R29qxY0=?=) APEL/10.7 Emacs/23.1 (x86_64-suse-linux-gnu) MULE/6.0 (HANACHIRUSATO) MIME-Version: 1.0 (generated by SEMI 1.14.6 - "Maruoka") Content-Type: text/plain; charset=US-ASCII Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org At Sat, 06 Feb 2010 10:46:26 -0500, Jody@Tritech wrote: > > On my AMD780V chipset, hda_intel.c can crash the kernel with a divide by > zero > for as-yet unknown reasons. A simple check for zero prevents it, though > the problem that causes it remains. Since the workaround is harmless and > won't affect anyone except victims of this bug, it should be safe; > moreover, > because this crash can be triggered by a user-mode application, there are > denial of service implications on the systems affected by the bug without > the patch. > Signed-off-by: Jody Bruchon Applied now. Thanks. Takashi > --- linux-2.6.33-rc6/sound/pci/hda/hda_intel.c 2010-01-29 > 16:57:50.000000000 -0500 > +++ linux-2.6.33-rc6-fix/sound/pci/hda/hda_intel.c 2010-02-06 > 09:44:10.028348166 -0500 > @@ -1878,6 +1878,12 @@ > > if (!bdl_pos_adj[chip->dev_index]) > return 1; /* no delayed ack */ > + if (azx_dev->period_bytes == 0) { > + printk(KERN_WARNING > + "hda-intel: Divide by zero was avoided " > + "in azx_dev->period_bytes.\n"); > + return 0; > + } > if (pos % azx_dev->period_bytes > azx_dev->period_bytes / 2) > return 0; /* NG - it's below the period boundary */ > return 1; /* OK, it's fine */ > > -- > To unsubscribe from this list: send the line "unsubscribe linux-kernel" in > the body of a message to majordomo@vger.kernel.org > More majordomo info at http://vger.kernel.org/majordomo-info.html > Please read the FAQ at http://www.tux.org/lkml/ >