]> git.ipfire.org Git - thirdparty/kernel/stable-queue.git/commitdiff
4.9-stable patches
authorGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Tue, 26 Apr 2022 06:43:27 +0000 (08:43 +0200)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Tue, 26 Apr 2022 06:43:27 +0000 (08:43 +0200)
added patches:
block-compat_ioctl-fix-range-check-in-blkgetsize.patch

queue-4.9/block-compat_ioctl-fix-range-check-in-blkgetsize.patch [new file with mode: 0644]
queue-4.9/series

diff --git a/queue-4.9/block-compat_ioctl-fix-range-check-in-blkgetsize.patch b/queue-4.9/block-compat_ioctl-fix-range-check-in-blkgetsize.patch
new file mode 100644 (file)
index 0000000..3fcf1d0
--- /dev/null
@@ -0,0 +1,36 @@
+From ccf16413e520164eb718cf8b22a30438da80ff23 Mon Sep 17 00:00:00 2001
+From: Khazhismel Kumykov <khazhy@google.com>
+Date: Thu, 14 Apr 2022 15:40:56 -0700
+Subject: block/compat_ioctl: fix range check in BLKGETSIZE
+
+From: Khazhismel Kumykov <khazhy@google.com>
+
+commit ccf16413e520164eb718cf8b22a30438da80ff23 upstream.
+
+kernel ulong and compat_ulong_t may not be same width. Use type directly
+to eliminate mismatches.
+
+This would result in truncation rather than EFBIG for 32bit mode for
+large disks.
+
+Reviewed-by: Bart Van Assche <bvanassche@acm.org>
+Signed-off-by: Khazhismel Kumykov <khazhy@google.com>
+Reviewed-by: Chaitanya Kulkarni <kch@nvidia.com>
+Link: https://lore.kernel.org/r/20220414224056.2875681-1-khazhy@google.com
+Signed-off-by: Jens Axboe <axboe@kernel.dk>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ block/compat_ioctl.c |    2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+--- a/block/compat_ioctl.c
++++ b/block/compat_ioctl.c
+@@ -394,7 +394,7 @@ long compat_blkdev_ioctl(struct file *fi
+               return 0;
+       case BLKGETSIZE:
+               size = i_size_read(bdev->bd_inode);
+-              if ((size >> 9) > ~0UL)
++              if ((size >> 9) > ~(compat_ulong_t)0)
+                       return -EFBIG;
+               return compat_put_ulong(arg, size >> 9);
index c50b66996052c2e8d97ff7a7c234813ff8dc3051..8d1b48cda3597efbce0b961d30bf20ffd3fa59f0 100644 (file)
@@ -21,3 +21,4 @@ arc-entry-fix-syscall_trace_exit-argument.patch
 ext4-limit-length-to-bitmap_maxbytes-blocksize-in-punch_hole.patch
 ext4-fix-overhead-calculation-to-account-for-the-reserved-gdt-blocks.patch
 ext4-force-overhead-calculation-if-the-s_overhead_cluster-makes-no-sense.patch
+block-compat_ioctl-fix-range-check-in-blkgetsize.patch