]> git.ipfire.org Git - thirdparty/kernel/stable-queue.git/commitdiff
4.9-stable patches
authorGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Wed, 26 May 2021 07:29:43 +0000 (09:29 +0200)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Wed, 26 May 2021 07:29:43 +0000 (09:29 +0200)
added patches:
video-hgafb-correctly-handle-card-detect-failure-during-probe.patch

queue-4.9/series
queue-4.9/video-hgafb-correctly-handle-card-detect-failure-during-probe.patch [new file with mode: 0644]

index 71cd254cdd93d36d0e1f5a7529a76456043e6def..d8a447f87904f1363165b12c99a8d6985070ac7d 100644 (file)
@@ -33,3 +33,4 @@ vgacon-record-video-mode-changes-with-vt_resizex.patch
 vt-fix-character-height-handling-with-vt_resizex.patch
 tty-vt-always-invoke-vc-vc_sw-con_resize-callback.patch
 iio-tsl2583-fix-division-by-a-zero-lux_val.patch
+video-hgafb-correctly-handle-card-detect-failure-during-probe.patch
diff --git a/queue-4.9/video-hgafb-correctly-handle-card-detect-failure-during-probe.patch b/queue-4.9/video-hgafb-correctly-handle-card-detect-failure-during-probe.patch
new file mode 100644 (file)
index 0000000..d4f9481
--- /dev/null
@@ -0,0 +1,43 @@
+From 02625c965239b71869326dd0461615f27307ecb3 Mon Sep 17 00:00:00 2001
+From: Anirudh Rayabharam <mail@anirudhrb.com>
+Date: Mon, 17 May 2021 00:57:14 +0530
+Subject: video: hgafb: correctly handle card detect failure during probe
+
+From: Anirudh Rayabharam <mail@anirudhrb.com>
+
+commit 02625c965239b71869326dd0461615f27307ecb3 upstream.
+
+The return value of hga_card_detect() is not properly handled causing
+the probe to succeed even though hga_card_detect() failed. Since probe
+succeeds, hgafb_open() can be called which will end up operating on an
+unmapped hga_vram. This results in an out-of-bounds access as reported
+by kernel test robot [1].
+
+To fix this, correctly detect failure of hga_card_detect() by checking
+for a non-zero error code.
+
+[1]: https://lore.kernel.org/lkml/20210516150019.GB25903@xsang-OptiPlex-9020/
+
+Fixes: dc13cac4862c ("video: hgafb: fix potential NULL pointer dereference")
+Cc: stable <stable@vger.kernel.org>
+Reported-by: kernel test robot <oliver.sang@intel.com>
+Reviewed-by: Igor Matheus Andrade Torrente <igormtorrente@gmail.com>
+Signed-off-by: Anirudh Rayabharam <mail@anirudhrb.com>
+Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
+Link: https://lore.kernel.org/r/20210516192714.25823-1-mail@anirudhrb.com
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ drivers/video/fbdev/hgafb.c |    2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+--- a/drivers/video/fbdev/hgafb.c
++++ b/drivers/video/fbdev/hgafb.c
+@@ -558,7 +558,7 @@ static int hgafb_probe(struct platform_d
+       int ret;
+       ret = hga_card_detect();
+-      if (!ret)
++      if (ret)
+               return ret;
+       printk(KERN_INFO "hgafb: %s with %ldK of memory detected.\n",