]> git.ipfire.org Git - thirdparty/kernel/stable-queue.git/commitdiff
4.4-stable patches
authorGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Wed, 14 Nov 2018 00:32:29 +0000 (16:32 -0800)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Wed, 14 Nov 2018 00:32:29 +0000 (16:32 -0800)
added patches:
cdrom-fix-improper-type-cast-which-can-leat-to-information-leak.patch

queue-4.4/cdrom-fix-improper-type-cast-which-can-leat-to-information-leak.patch [new file with mode: 0644]
queue-4.4/series

diff --git a/queue-4.4/cdrom-fix-improper-type-cast-which-can-leat-to-information-leak.patch b/queue-4.4/cdrom-fix-improper-type-cast-which-can-leat-to-information-leak.patch
new file mode 100644 (file)
index 0000000..df551a6
--- /dev/null
@@ -0,0 +1,35 @@
+From e4f3aa2e1e67bb48dfbaaf1cad59013d5a5bc276 Mon Sep 17 00:00:00 2001
+From: Young_X <YangX92@hotmail.com>
+Date: Wed, 3 Oct 2018 12:54:29 +0000
+Subject: cdrom: fix improper type cast, which can leat to information leak.
+
+From: Young_X <YangX92@hotmail.com>
+
+commit e4f3aa2e1e67bb48dfbaaf1cad59013d5a5bc276 upstream.
+
+There is another cast from unsigned long to int which causes
+a bounds check to fail with specially crafted input. The value is
+then used as an index in the slot array in cdrom_slot_status().
+
+This issue is similar to CVE-2018-16658 and CVE-2018-10940.
+
+Signed-off-by: Young_X <YangX92@hotmail.com>
+Signed-off-by: Jens Axboe <axboe@kernel.dk>
+Cc: Ben Hutchings <ben.hutchings@codethink.co.uk>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+
+---
+ drivers/cdrom/cdrom.c |    2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+--- a/drivers/cdrom/cdrom.c
++++ b/drivers/cdrom/cdrom.c
+@@ -2425,7 +2425,7 @@ static int cdrom_ioctl_select_disc(struc
+               return -ENOSYS;
+       if (arg != CDSL_CURRENT && arg != CDSL_NONE) {
+-              if ((int)arg >= cdi->capacity)
++              if (arg >= cdi->capacity)
+                       return -EINVAL;
+       }
index e03189d568079079fb283b91c5854bc89c55c52f..6a5e56ce9e4260ae7638c8b1215690cd90eeb922 100644 (file)
@@ -105,3 +105,4 @@ sc16is7xx-fix-for-multi-channel-stall.patch
 media-tvp5150-fix-width-alignment-during-set_selection.patch
 9p-locks-fix-glock.client_id-leak-in-do_lock.patch
 9p-clear-dangling-pointers-in-p9stat_free.patch
+cdrom-fix-improper-type-cast-which-can-leat-to-information-leak.patch