]> git.ipfire.org Git - thirdparty/kernel/stable-queue.git/commitdiff
5.10-stable patches
authorGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Tue, 26 Apr 2022 06:44:03 +0000 (08:44 +0200)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Tue, 26 Apr 2022 06:44:03 +0000 (08:44 +0200)
added patches:
block-compat_ioctl-fix-range-check-in-blkgetsize.patch

queue-5.10/block-compat_ioctl-fix-range-check-in-blkgetsize.patch [new file with mode: 0644]
queue-5.10/series

diff --git a/queue-5.10/block-compat_ioctl-fix-range-check-in-blkgetsize.patch b/queue-5.10/block-compat_ioctl-fix-range-check-in-blkgetsize.patch
new file mode 100644 (file)
index 0000000..539ab91
--- /dev/null
@@ -0,0 +1,36 @@
+From ccf16413e520164eb718cf8b22a30438da80ff23 Mon Sep 17 00:00:00 2001
+From: Khazhismel Kumykov <khazhy@google.com>
+Date: Thu, 14 Apr 2022 15:40:56 -0700
+Subject: block/compat_ioctl: fix range check in BLKGETSIZE
+
+From: Khazhismel Kumykov <khazhy@google.com>
+
+commit ccf16413e520164eb718cf8b22a30438da80ff23 upstream.
+
+kernel ulong and compat_ulong_t may not be same width. Use type directly
+to eliminate mismatches.
+
+This would result in truncation rather than EFBIG for 32bit mode for
+large disks.
+
+Reviewed-by: Bart Van Assche <bvanassche@acm.org>
+Signed-off-by: Khazhismel Kumykov <khazhy@google.com>
+Reviewed-by: Chaitanya Kulkarni <kch@nvidia.com>
+Link: https://lore.kernel.org/r/20220414224056.2875681-1-khazhy@google.com
+Signed-off-by: Jens Axboe <axboe@kernel.dk>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ block/ioctl.c |    2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+--- a/block/ioctl.c
++++ b/block/ioctl.c
+@@ -679,7 +679,7 @@ long compat_blkdev_ioctl(struct file *fi
+                              (bdev->bd_bdi->ra_pages * PAGE_SIZE) / 512);
+       case BLKGETSIZE:
+               size = i_size_read(bdev->bd_inode);
+-              if ((size >> 9) > ~0UL)
++              if ((size >> 9) > ~(compat_ulong_t)0)
+                       return -EFBIG;
+               return compat_put_ulong(argp, size >> 9);
index 2a4d3bb5ee1200a4a89ffe5c48ec7754f7f9be89..6cb72050b47ef79d7fb586f96aeac554db859edb 100644 (file)
@@ -82,3 +82,4 @@ can-isotp-stop-timeout-monitoring-when-no-first-frame-was-sent.patch
 jbd2-fix-a-potential-race-while-discarding-reserved-buffers-after-an-abort.patch
 spi-atmel-quadspi-fix-the-buswidth-adjustment-between-spi-mem-and-controller.patch
 staging-ion-prevent-incorrect-reference-counting-behavour.patch
+block-compat_ioctl-fix-range-check-in-blkgetsize.patch