]> git.ipfire.org Git - thirdparty/kernel/stable-queue.git/blob - releases/4.14.7/dvb_frontend-don-t-use-after-free-the-frontend-struct.patch
Fixes for 5.10
[thirdparty/kernel/stable-queue.git] / releases / 4.14.7 / dvb_frontend-don-t-use-after-free-the-frontend-struct.patch
1 From b1cb7372fa822af6c06c8045963571d13ad6348b Mon Sep 17 00:00:00 2001
2 From: Mauro Carvalho Chehab <mchehab@s-opensource.com>
3 Date: Tue, 7 Nov 2017 08:39:39 -0500
4 Subject: dvb_frontend: don't use-after-free the frontend struct
5
6 From: Mauro Carvalho Chehab <mchehab@s-opensource.com>
7
8 commit b1cb7372fa822af6c06c8045963571d13ad6348b upstream.
9
10 dvb_frontend_invoke_release() may free the frontend struct.
11 So, the free logic can't update it anymore after calling it.
12
13 That's OK, as __dvb_frontend_free() is called only when the
14 krefs are zeroed, so nobody is using it anymore.
15
16 That should fix the following KASAN error:
17
18 The KASAN report looks like this (running on kernel 3e0cc09a3a2c40ec1ffb6b4e12da86e98feccb11 (4.14-rc5+)):
19 ==================================================================
20 BUG: KASAN: use-after-free in __dvb_frontend_free+0x113/0x120
21 Write of size 8 at addr ffff880067d45a00 by task kworker/0:1/24
22
23 CPU: 0 PID: 24 Comm: kworker/0:1 Not tainted 4.14.0-rc5-43687-g06ab8a23e0e6 #545
24 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Bochs 01/01/2011
25 Workqueue: usb_hub_wq hub_event
26 Call Trace:
27 __dump_stack lib/dump_stack.c:16
28 dump_stack+0x292/0x395 lib/dump_stack.c:52
29 print_address_description+0x78/0x280 mm/kasan/report.c:252
30 kasan_report_error mm/kasan/report.c:351
31 kasan_report+0x23d/0x350 mm/kasan/report.c:409
32 __asan_report_store8_noabort+0x1c/0x20 mm/kasan/report.c:435
33 __dvb_frontend_free+0x113/0x120 drivers/media/dvb-core/dvb_frontend.c:156
34 dvb_frontend_put+0x59/0x70 drivers/media/dvb-core/dvb_frontend.c:176
35 dvb_frontend_detach+0x120/0x150 drivers/media/dvb-core/dvb_frontend.c:2803
36 dvb_usb_adapter_frontend_exit+0xd6/0x160 drivers/media/usb/dvb-usb/dvb-usb-dvb.c:340
37 dvb_usb_adapter_exit drivers/media/usb/dvb-usb/dvb-usb-init.c:116
38 dvb_usb_exit+0x9b/0x200 drivers/media/usb/dvb-usb/dvb-usb-init.c:132
39 dvb_usb_device_exit+0xa5/0xf0 drivers/media/usb/dvb-usb/dvb-usb-init.c:295
40 usb_unbind_interface+0x21c/0xa90 drivers/usb/core/driver.c:423
41 __device_release_driver drivers/base/dd.c:861
42 device_release_driver_internal+0x4f1/0x5c0 drivers/base/dd.c:893
43 device_release_driver+0x1e/0x30 drivers/base/dd.c:918
44 bus_remove_device+0x2f4/0x4b0 drivers/base/bus.c:565
45 device_del+0x5c4/0xab0 drivers/base/core.c:1985
46 usb_disable_device+0x1e9/0x680 drivers/usb/core/message.c:1170
47 usb_disconnect+0x260/0x7a0 drivers/usb/core/hub.c:2124
48 hub_port_connect drivers/usb/core/hub.c:4754
49 hub_port_connect_change drivers/usb/core/hub.c:5009
50 port_event drivers/usb/core/hub.c:5115
51 hub_event+0x1318/0x3740 drivers/usb/core/hub.c:5195
52 process_one_work+0xc73/0x1d90 kernel/workqueue.c:2119
53 worker_thread+0x221/0x1850 kernel/workqueue.c:2253
54 kthread+0x363/0x440 kernel/kthread.c:231
55 ret_from_fork+0x2a/0x40 arch/x86/entry/entry_64.S:431
56
57 Allocated by task 24:
58 save_stack_trace+0x1b/0x20 arch/x86/kernel/stacktrace.c:59
59 save_stack+0x43/0xd0 mm/kasan/kasan.c:447
60 set_track mm/kasan/kasan.c:459
61 kasan_kmalloc+0xad/0xe0 mm/kasan/kasan.c:551
62 kmem_cache_alloc_trace+0x11e/0x2d0 mm/slub.c:2772
63 kmalloc ./include/linux/slab.h:493
64 kzalloc ./include/linux/slab.h:666
65 dtt200u_fe_attach+0x4c/0x110 drivers/media/usb/dvb-usb/dtt200u-fe.c:212
66 dtt200u_frontend_attach+0x35/0x80 drivers/media/usb/dvb-usb/dtt200u.c:136
67 dvb_usb_adapter_frontend_init+0x32b/0x660 drivers/media/usb/dvb-usb/dvb-usb-dvb.c:286
68 dvb_usb_adapter_init drivers/media/usb/dvb-usb/dvb-usb-init.c:86
69 dvb_usb_init drivers/media/usb/dvb-usb/dvb-usb-init.c:162
70 dvb_usb_device_init+0xf73/0x17f0 drivers/media/usb/dvb-usb/dvb-usb-init.c:277
71 dtt200u_usb_probe+0xa1/0xe0 drivers/media/usb/dvb-usb/dtt200u.c:155
72 usb_probe_interface+0x35d/0x8e0 drivers/usb/core/driver.c:361
73 really_probe drivers/base/dd.c:413
74 driver_probe_device+0x610/0xa00 drivers/base/dd.c:557
75 __device_attach_driver+0x230/0x290 drivers/base/dd.c:653
76 bus_for_each_drv+0x161/0x210 drivers/base/bus.c:463
77 __device_attach+0x26b/0x3c0 drivers/base/dd.c:710
78 device_initial_probe+0x1f/0x30 drivers/base/dd.c:757
79 bus_probe_device+0x1eb/0x290 drivers/base/bus.c:523
80 device_add+0xd0b/0x1660 drivers/base/core.c:1835
81 usb_set_configuration+0x104e/0x1870 drivers/usb/core/message.c:1932
82 generic_probe+0x73/0xe0 drivers/usb/core/generic.c:174
83 usb_probe_device+0xaf/0xe0 drivers/usb/core/driver.c:266
84 really_probe drivers/base/dd.c:413
85 driver_probe_device+0x610/0xa00 drivers/base/dd.c:557
86 __device_attach_driver+0x230/0x290 drivers/base/dd.c:653
87 bus_for_each_drv+0x161/0x210 drivers/base/bus.c:463
88 __device_attach+0x26b/0x3c0 drivers/base/dd.c:710
89 device_initial_probe+0x1f/0x30 drivers/base/dd.c:757
90 bus_probe_device+0x1eb/0x290 drivers/base/bus.c:523
91 device_add+0xd0b/0x1660 drivers/base/core.c:1835
92 usb_new_device+0x7b8/0x1020 drivers/usb/core/hub.c:2457
93 hub_port_connect drivers/usb/core/hub.c:4903
94 hub_port_connect_change drivers/usb/core/hub.c:5009
95 port_event drivers/usb/core/hub.c:5115
96 hub_event+0x194d/0x3740 drivers/usb/core/hub.c:5195
97 process_one_work+0xc73/0x1d90 kernel/workqueue.c:2119
98 worker_thread+0x221/0x1850 kernel/workqueue.c:2253
99 kthread+0x363/0x440 kernel/kthread.c:231
100 ret_from_fork+0x2a/0x40 arch/x86/entry/entry_64.S:431
101
102 Freed by task 24:
103 save_stack_trace+0x1b/0x20 arch/x86/kernel/stacktrace.c:59
104 save_stack+0x43/0xd0 mm/kasan/kasan.c:447
105 set_track mm/kasan/kasan.c:459
106 kasan_slab_free+0x72/0xc0 mm/kasan/kasan.c:524
107 slab_free_hook mm/slub.c:1390
108 slab_free_freelist_hook mm/slub.c:1412
109 slab_free mm/slub.c:2988
110 kfree+0xf6/0x2f0 mm/slub.c:3919
111 dtt200u_fe_release+0x3c/0x50 drivers/media/usb/dvb-usb/dtt200u-fe.c:202
112 dvb_frontend_invoke_release.part.13+0x1c/0x30 drivers/media/dvb-core/dvb_frontend.c:2790
113 dvb_frontend_invoke_release drivers/media/dvb-core/dvb_frontend.c:2789
114 __dvb_frontend_free+0xad/0x120 drivers/media/dvb-core/dvb_frontend.c:153
115 dvb_frontend_put+0x59/0x70 drivers/media/dvb-core/dvb_frontend.c:176
116 dvb_frontend_detach+0x120/0x150 drivers/media/dvb-core/dvb_frontend.c:2803
117 dvb_usb_adapter_frontend_exit+0xd6/0x160 drivers/media/usb/dvb-usb/dvb-usb-dvb.c:340
118 dvb_usb_adapter_exit drivers/media/usb/dvb-usb/dvb-usb-init.c:116
119 dvb_usb_exit+0x9b/0x200 drivers/media/usb/dvb-usb/dvb-usb-init.c:132
120 dvb_usb_device_exit+0xa5/0xf0 drivers/media/usb/dvb-usb/dvb-usb-init.c:295
121 usb_unbind_interface+0x21c/0xa90 drivers/usb/core/driver.c:423
122 __device_release_driver drivers/base/dd.c:861
123 device_release_driver_internal+0x4f1/0x5c0 drivers/base/dd.c:893
124 device_release_driver+0x1e/0x30 drivers/base/dd.c:918
125 bus_remove_device+0x2f4/0x4b0 drivers/base/bus.c:565
126 device_del+0x5c4/0xab0 drivers/base/core.c:1985
127 usb_disable_device+0x1e9/0x680 drivers/usb/core/message.c:1170
128 usb_disconnect+0x260/0x7a0 drivers/usb/core/hub.c:2124
129 hub_port_connect drivers/usb/core/hub.c:4754
130 hub_port_connect_change drivers/usb/core/hub.c:5009
131 port_event drivers/usb/core/hub.c:5115
132 hub_event+0x1318/0x3740 drivers/usb/core/hub.c:5195
133 process_one_work+0xc73/0x1d90 kernel/workqueue.c:2119
134 worker_thread+0x221/0x1850 kernel/workqueue.c:2253
135 kthread+0x363/0x440 kernel/kthread.c:231
136 ret_from_fork+0x2a/0x40 arch/x86/entry/entry_64.S:431
137
138 The buggy address belongs to the object at ffff880067d45500
139 which belongs to the cache kmalloc-2048 of size 2048
140 The buggy address is located 1280 bytes inside of
141 2048-byte region [ffff880067d45500, ffff880067d45d00)
142 The buggy address belongs to the page:
143 page:ffffea00019f5000 count:1 mapcount:0 mapping: (null)
144 index:0x0 compound_mapcount: 0
145 flags: 0x100000000008100(slab|head)
146 raw: 0100000000008100 0000000000000000 0000000000000000 00000001000f000f
147 raw: dead000000000100 dead000000000200 ffff88006c002d80 0000000000000000
148 page dumped because: kasan: bad access detected
149
150 Memory state around the buggy address:
151 ffff880067d45900: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
152 ffff880067d45980: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
153 ffff880067d45a00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
154 ^
155 ffff880067d45a80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
156 ffff880067d45b00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
157 ==================================================================
158
159 Fixes: ead666000a5f ("media: dvb_frontend: only use kref after initialized")
160
161 Reported-by: Andrey Konovalov <andreyknvl@google.com>
162 Suggested-by: Matthias Schwarzott <zzam@gentoo.org>
163 Tested-by: Andrey Konovalov <andreyknvl@google.com>
164 Signed-off-by: Mauro Carvalho Chehab <mchehab@s-opensource.com>
165 Cc: Guenter Roeck <linux@roeck-us.net>
166 Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
167
168 ---
169 drivers/media/dvb-core/dvb_frontend.c | 7 ++-----
170 1 file changed, 2 insertions(+), 5 deletions(-)
171
172 --- a/drivers/media/dvb-core/dvb_frontend.c
173 +++ b/drivers/media/dvb-core/dvb_frontend.c
174 @@ -150,11 +150,8 @@ static void __dvb_frontend_free(struct d
175
176 dvb_frontend_invoke_release(fe, fe->ops.release);
177
178 - if (!fepriv)
179 - return;
180 -
181 - kfree(fepriv);
182 - fe->frontend_priv = NULL;
183 + if (fepriv)
184 + kfree(fepriv);
185 }
186
187 static void dvb_frontend_free(struct kref *ref)