mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] firewire: fix NULL pointer deref. and resource leak
       [not found]                 ` <47BC8302.6040200@s5r6.in-berlin.de>
@ 2008-02-20 20:10                   ` Stefan Richter
  0 siblings, 0 replies; only message in thread
From: Stefan Richter @ 2008-02-20 20:10 UTC (permalink / raw)
  To: linux1394-devel; +Cc: Anders Blomdell, David Moore, linux-kernel

By supplying ioctl()s in the wrong order, a userspace client was able to
trigger NULL pointer dereferences.  Furthermore, by calling
ioctl_create_iso_context more than once, new contexts could be created
without ever freeing the previously created contexts.

Thanks to Anders Blomdell for the report.

Signed-off-by: Stefan Richter <stefanr@s5r6.in-berlin.de>
---
 drivers/firewire/fw-cdev.c |    9 +++++++--
 1 file changed, 7 insertions(+), 2 deletions(-)

Index: linux/drivers/firewire/fw-cdev.c
===================================================================
--- linux.orig/drivers/firewire/fw-cdev.c
+++ linux/drivers/firewire/fw-cdev.c
@@ -646,6 +646,10 @@ static int ioctl_create_iso_context(stru
 	struct fw_cdev_create_iso_context *request = buffer;
 	struct fw_iso_context *context;
 
+	/* We only support one context at this time. */
+	if (client->iso_context != NULL)
+		return -EBUSY;
+
 	if (request->channel > 63)
 		return -EINVAL;
 
@@ -792,8 +796,9 @@ static int ioctl_start_iso(struct client
 {
 	struct fw_cdev_start_iso *request = buffer;
 
-	if (request->handle != 0)
+	if (client->iso_context == NULL || request->handle != 0)
 		return -EINVAL;
+
 	if (client->iso_context->type == FW_ISO_CONTEXT_RECEIVE) {
 		if (request->tags == 0 || request->tags > 15)
 			return -EINVAL;
@@ -810,7 +815,7 @@ static int ioctl_stop_iso(struct client 
 {
 	struct fw_cdev_stop_iso *request = buffer;
 
-	if (request->handle != 0)
+	if (client->iso_context == NULL || request->handle != 0)
 		return -EINVAL;
 
 	return fw_iso_context_stop(client->iso_context);

-- 
Stefan Richter
-=====-==--- --=- =-=--
http://arcgraph.de/sr/


^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2008-02-20 20:12 UTC | newest]

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
     [not found] <47BB0F99.3080101@control.lth.se>
     [not found] ` <1203446333.28871.8.camel@aries.csail.mit.edu>
     [not found]   ` <47BC48A1.2010105@control.lth.se>
     [not found]     ` <47BC51C9.6000102@control.lth.se>
     [not found]       ` <1203524791.21593.31.camel@pisces.mit.edu>
     [not found]         ` <47BC5753.9000306@control.lth.se>
     [not found]           ` <1203528165.21593.47.camel@pisces.mit.edu>
     [not found]             ` <47BC6E15.9000001@control.lth.se>
     [not found]               ` <47BC7210.7040300@control.lth.se>
     [not found]                 ` <47BC8302.6040200@s5r6.in-berlin.de>
2008-02-20 20:10                   ` [PATCH] firewire: fix NULL pointer deref. and resource leak Stefan Richter

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®