]> git.ipfire.org Git - thirdparty/kernel/stable-queue.git/commitdiff
4.14-stable patches
authorGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Sun, 17 May 2020 15:29:19 +0000 (17:29 +0200)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Sun, 17 May 2020 15:29:19 +0000 (17:29 +0200)
added patches:
net-phy-micrel-use-strlcpy-for-ethtool-get_strings.patch

queue-4.14/net-phy-micrel-use-strlcpy-for-ethtool-get_strings.patch [new file with mode: 0644]
queue-4.14/series

diff --git a/queue-4.14/net-phy-micrel-use-strlcpy-for-ethtool-get_strings.patch b/queue-4.14/net-phy-micrel-use-strlcpy-for-ethtool-get_strings.patch
new file mode 100644 (file)
index 0000000..5f9f573
--- /dev/null
@@ -0,0 +1,37 @@
+From 55f53567afe5f0cd2fd9e006b174c08c31c466f8 Mon Sep 17 00:00:00 2001
+From: Florian Fainelli <f.fainelli@gmail.com>
+Date: Fri, 2 Mar 2018 15:08:38 -0800
+Subject: net: phy: micrel: Use strlcpy() for ethtool::get_strings
+
+From: Florian Fainelli <f.fainelli@gmail.com>
+
+commit 55f53567afe5f0cd2fd9e006b174c08c31c466f8 upstream.
+
+Our statistics strings are allocated at initialization without being
+bound to a specific size, yet, we would copy ETH_GSTRING_LEN bytes using
+memcpy() which would create out of bounds accesses, this was flagged by
+KASAN. Replace this with strlcpy() to make sure we are bound the source
+buffer size and we also always NUL-terminate strings.
+
+Fixes: 2b2427d06426 ("phy: micrel: Add ethtool statistics counters")
+Signed-off-by: Florian Fainelli <f.fainelli@gmail.com>
+Signed-off-by: David S. Miller <davem@davemloft.net>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+
+---
+ drivers/net/phy/micrel.c |    4 ++--
+ 1 file changed, 2 insertions(+), 2 deletions(-)
+
+--- a/drivers/net/phy/micrel.c
++++ b/drivers/net/phy/micrel.c
+@@ -674,8 +674,8 @@ static void kszphy_get_strings(struct ph
+       int i;
+       for (i = 0; i < ARRAY_SIZE(kszphy_hw_stats); i++) {
+-              memcpy(data + i * ETH_GSTRING_LEN,
+-                     kszphy_hw_stats[i].string, ETH_GSTRING_LEN);
++              strlcpy(data + i * ETH_GSTRING_LEN,
++                      kszphy_hw_stats[i].string, ETH_GSTRING_LEN);
+       }
+ }
index 1583015ab40f2ee61d66e300aca4a0047dbdcc62..2b906e153a1d1b52af1ce5b01552231de70b8e09 100644 (file)
@@ -77,3 +77,4 @@ gcc-10-disable-stringop-overflow-warning-for-now.patch
 gcc-10-disable-restrict-warning-for-now.patch
 gcc-10-avoid-shadowing-standard-library-free-in-crypto.patch
 x86-asm-add-instruction-suffixes-to-bitops.patch
+net-phy-micrel-use-strlcpy-for-ethtool-get_strings.patch