]> git.ipfire.org Git - thirdparty/kernel/stable-queue.git/blame - releases/2.6.36.2/usb-misc-sisusbvga-fix-information-leak-to-userland.patch
Fixes for 5.10
[thirdparty/kernel/stable-queue.git] / releases / 2.6.36.2 / usb-misc-sisusbvga-fix-information-leak-to-userland.patch
CommitLineData
eaad4d6c
GKH
1From 5dc92cf1d0b4b0debbd2e333b83f9746c103533d Mon Sep 17 00:00:00 2001
2From: Vasiliy Kulikov <segooon@gmail.com>
3Date: Sat, 6 Nov 2010 17:41:35 +0300
4Subject: usb: misc: sisusbvga: fix information leak to userland
5
6From: Vasiliy Kulikov <segooon@gmail.com>
7
8commit 5dc92cf1d0b4b0debbd2e333b83f9746c103533d upstream.
9
10Structure sisusb_info is copied to userland with "sisusb_reserved" field
11uninitialized. It leads to leaking of contents of kernel stack memory.
12
13Signed-off-by: Vasiliy Kulikov <segooon@gmail.com>
14Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
15
16---
17 drivers/usb/misc/sisusbvga/sisusb.c | 1 +
18 1 file changed, 1 insertion(+)
19
20--- a/drivers/usb/misc/sisusbvga/sisusb.c
21+++ b/drivers/usb/misc/sisusbvga/sisusb.c
22@@ -3008,6 +3008,7 @@ sisusb_ioctl(struct file *file, unsigned
23 #else
24 x.sisusb_conactive = 0;
25 #endif
26+ memset(x.sisusb_reserved, 0, sizeof(x.sisusb_reserved));
27
28 if (copy_to_user((void __user *)arg, &x, sizeof(x)))
29 retval = -EFAULT;