]> git.ipfire.org Git - thirdparty/kernel/stable-queue.git/commitdiff
4.9-stable patches
authorGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Fri, 22 Sep 2017 11:19:10 +0000 (13:19 +0200)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Fri, 22 Sep 2017 11:19:10 +0000 (13:19 +0200)
added patches:
scsi-qla2xxx-correction-to-vha-vref_count-timeout.patch
scsi-qla2xxx-fix-an-integer-overflow-in-sysfs-code.patch
scsi-sg-fixup-infoleak-when-using-sg_get_request_table.patch

queue-4.9/scsi-qla2xxx-correction-to-vha-vref_count-timeout.patch [new file with mode: 0644]
queue-4.9/scsi-qla2xxx-fix-an-integer-overflow-in-sysfs-code.patch [new file with mode: 0644]
queue-4.9/scsi-sg-fixup-infoleak-when-using-sg_get_request_table.patch [new file with mode: 0644]
queue-4.9/series

diff --git a/queue-4.9/scsi-qla2xxx-correction-to-vha-vref_count-timeout.patch b/queue-4.9/scsi-qla2xxx-correction-to-vha-vref_count-timeout.patch
new file mode 100644 (file)
index 0000000..5a621eb
--- /dev/null
@@ -0,0 +1,32 @@
+From 6e98095f8fb6d98da34c4e6c34e69e7c638d79c0 Mon Sep 17 00:00:00 2001
+From: Joe Carnuccio <joe.carnuccio@cavium.com>
+Date: Wed, 23 Aug 2017 15:04:55 -0700
+Subject: scsi: qla2xxx: Correction to vha->vref_count timeout
+
+From: Joe Carnuccio <joe.carnuccio@cavium.com>
+
+commit 6e98095f8fb6d98da34c4e6c34e69e7c638d79c0 upstream.
+
+Fix incorrect second argument for wait_event_timeout()
+
+Fixes: c4a9b538ab2a ("qla2xxx: Allow vref count to timeout on vport delete.")
+Signed-off-by: Joe Carnuccio <joe.carnuccio@cavium.com>
+Signed-off-by: Himanshu Madhani <himanshu.madhani@cavium.com>
+Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+
+---
+ drivers/scsi/qla2xxx/qla_mid.c |    2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+--- a/drivers/scsi/qla2xxx/qla_mid.c
++++ b/drivers/scsi/qla2xxx/qla_mid.c
+@@ -74,7 +74,7 @@ qla24xx_deallocate_vp_id(scsi_qla_host_t
+        * ensures no active vp_list traversal while the vport is removed
+        * from the queue)
+        */
+-      wait_event_timeout(vha->vref_waitq, atomic_read(&vha->vref_count),
++      wait_event_timeout(vha->vref_waitq, !atomic_read(&vha->vref_count),
+           10*HZ);
+       spin_lock_irqsave(&ha->vport_slock, flags);
diff --git a/queue-4.9/scsi-qla2xxx-fix-an-integer-overflow-in-sysfs-code.patch b/queue-4.9/scsi-qla2xxx-fix-an-integer-overflow-in-sysfs-code.patch
new file mode 100644 (file)
index 0000000..e6949cf
--- /dev/null
@@ -0,0 +1,62 @@
+From e6f77540c067b48dee10f1e33678415bfcc89017 Mon Sep 17 00:00:00 2001
+From: Dan Carpenter <dan.carpenter@oracle.com>
+Date: Wed, 30 Aug 2017 16:30:35 +0300
+Subject: scsi: qla2xxx: Fix an integer overflow in sysfs code
+
+From: Dan Carpenter <dan.carpenter@oracle.com>
+
+commit e6f77540c067b48dee10f1e33678415bfcc89017 upstream.
+
+The value of "size" comes from the user.  When we add "start + size" it
+could lead to an integer overflow bug.
+
+It means we vmalloc() a lot more memory than we had intended.  I believe
+that on 64 bit systems vmalloc() can succeed even if we ask it to
+allocate huge 4GB buffers.  So we would get memory corruption and likely
+a crash when we call ha->isp_ops->write_optrom() and ->read_optrom().
+
+Only root can trigger this bug.
+
+Link: https://bugzilla.kernel.org/show_bug.cgi?id=194061
+
+Fixes: b7cc176c9eb3 ("[SCSI] qla2xxx: Allow region-based flash-part accesses.")
+Reported-by: shqking <shqking@gmail.com>
+Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
+Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+
+---
+ drivers/scsi/qla2xxx/qla_attr.c |    8 ++++----
+ 1 file changed, 4 insertions(+), 4 deletions(-)
+
+--- a/drivers/scsi/qla2xxx/qla_attr.c
++++ b/drivers/scsi/qla2xxx/qla_attr.c
+@@ -318,6 +318,8 @@ qla2x00_sysfs_write_optrom_ctl(struct fi
+               return -EINVAL;
+       if (start > ha->optrom_size)
+               return -EINVAL;
++      if (size > ha->optrom_size - start)
++              size = ha->optrom_size - start;
+       mutex_lock(&ha->optrom_mutex);
+       switch (val) {
+@@ -343,8 +345,7 @@ qla2x00_sysfs_write_optrom_ctl(struct fi
+               }
+               ha->optrom_region_start = start;
+-              ha->optrom_region_size = start + size > ha->optrom_size ?
+-                  ha->optrom_size - start : size;
++              ha->optrom_region_size = start + size;
+               ha->optrom_state = QLA_SREADING;
+               ha->optrom_buffer = vmalloc(ha->optrom_region_size);
+@@ -417,8 +418,7 @@ qla2x00_sysfs_write_optrom_ctl(struct fi
+               }
+               ha->optrom_region_start = start;
+-              ha->optrom_region_size = start + size > ha->optrom_size ?
+-                  ha->optrom_size - start : size;
++              ha->optrom_region_size = start + size;
+               ha->optrom_state = QLA_SWRITING;
+               ha->optrom_buffer = vmalloc(ha->optrom_region_size);
diff --git a/queue-4.9/scsi-sg-fixup-infoleak-when-using-sg_get_request_table.patch b/queue-4.9/scsi-sg-fixup-infoleak-when-using-sg_get_request_table.patch
new file mode 100644 (file)
index 0000000..6ade3bf
--- /dev/null
@@ -0,0 +1,46 @@
+From 3e0097499839e0fe3af380410eababe5a47c4cf9 Mon Sep 17 00:00:00 2001
+From: Hannes Reinecke <hare@suse.de>
+Date: Fri, 15 Sep 2017 14:05:16 +0200
+Subject: scsi: sg: fixup infoleak when using SG_GET_REQUEST_TABLE
+
+From: Hannes Reinecke <hare@suse.de>
+
+commit 3e0097499839e0fe3af380410eababe5a47c4cf9 upstream.
+
+When calling SG_GET_REQUEST_TABLE ioctl only a half-filled table is
+returned; the remaining part will then contain stale kernel memory
+information.  This patch zeroes out the entire table to avoid this
+issue.
+
+Signed-off-by: Hannes Reinecke <hare@suse.com>
+Reviewed-by: Bart Van Assche <bart.vanassche@wdc.com>
+Reviewed-by: Christoph Hellwig <hch@lst.de>
+Reviewed-by: Eric Dumazet <edumazet@google.com>
+Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+
+---
+ drivers/scsi/sg.c |    5 ++---
+ 1 file changed, 2 insertions(+), 3 deletions(-)
+
+--- a/drivers/scsi/sg.c
++++ b/drivers/scsi/sg.c
+@@ -839,7 +839,6 @@ sg_fill_request_table(Sg_fd *sfp, sg_req
+       list_for_each_entry(srp, &sfp->rq_list, entry) {
+               if (val > SG_MAX_QUEUE)
+                       break;
+-              memset(&rinfo[val], 0, SZ_SG_REQ_INFO);
+               rinfo[val].req_state = srp->done + 1;
+               rinfo[val].problem =
+                       srp->header.masked_status &
+@@ -1057,8 +1056,8 @@ sg_ioctl(struct file *filp, unsigned int
+               else {
+                       sg_req_info_t *rinfo;
+-                      rinfo = kmalloc(SZ_SG_REQ_INFO * SG_MAX_QUEUE,
+-                                                              GFP_KERNEL);
++                      rinfo = kzalloc(SZ_SG_REQ_INFO * SG_MAX_QUEUE,
++                                      GFP_KERNEL);
+                       if (!rinfo)
+                               return -ENOMEM;
+                       read_lock_irqsave(&sfp->rq_list_lock, iflags);
index 24e69cd6d5a12dfac9ba62f28dd3c7d64aaaa080..8a09b971e529eed25f00a839084b4fda005d8863 100644 (file)
@@ -48,3 +48,6 @@ scsi-sg-remove-save_scat_len.patch
 scsi-sg-use-standard-lists-for-sg_requests.patch
 scsi-sg-off-by-one-in-sg_ioctl.patch
 scsi-sg-factor-out-sg_fill_request_table.patch
+scsi-sg-fixup-infoleak-when-using-sg_get_request_table.patch
+scsi-qla2xxx-correction-to-vha-vref_count-timeout.patch
+scsi-qla2xxx-fix-an-integer-overflow-in-sysfs-code.patch