]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
media, bpf: Do not copy more entries than user space requested
authorSean Young <sean@mess.org>
Wed, 23 Jun 2021 21:37:54 +0000 (22:37 +0100)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Mon, 19 Jul 2021 08:01:08 +0000 (10:01 +0200)
[ Upstream commit 647d446d66e493d23ca1047fa8492b0269674530 ]

The syscall bpf(BPF_PROG_QUERY, &attr) should use the prog_cnt field to
see how many entries user space provided and return ENOSPC if there are
more programs than that. Before this patch, this is not checked and
ENOSPC is never returned.

Note that one lirc device is limited to 64 bpf programs, and user space
I'm aware of -- ir-keytable -- always gives enough space for 64 entries
already. However, we should not copy program ids than are requested.

Signed-off-by: Sean Young <sean@mess.org>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Link: https://lore.kernel.org/bpf/20210623213754.632-1-sean@mess.org
Signed-off-by: Sasha Levin <sashal@kernel.org>
drivers/media/rc/bpf-lirc.c

index 3fe3edd8087656013846c33d3ac690d4700f542f..afae0afe3f810e969fe090d95c94c4ffcb93d229 100644 (file)
@@ -326,7 +326,8 @@ int lirc_prog_query(const union bpf_attr *attr, union bpf_attr __user *uattr)
        }
 
        if (attr->query.prog_cnt != 0 && prog_ids && cnt)
-               ret = bpf_prog_array_copy_to_user(progs, prog_ids, cnt);
+               ret = bpf_prog_array_copy_to_user(progs, prog_ids,
+                                                 attr->query.prog_cnt);
 
 unlock:
        mutex_unlock(&ir_raw_handler_lock);