[PATCH] isdn: Disable IIOCDBGVAR

Subsystems: the rest

STALE2917d

2 messages, 2 authors, 2018-08-16 · open the first message on its own page

[PATCH] isdn: Disable IIOCDBGVAR

From: Kees Cook <hidden>
Date: 2018-08-15 19:14:12

It was possible to directly leak the kernel address where the isdn_dev
structure pointer was stored. This is a kernel ASLR bypass for anyone
with access to the ioctl. The code had been present since the beginning
of git history, though this shouldn't ever be needed for normal operation,
therefore remove it.

Reported-by: Al Viro <viro@zeniv.linux.org.uk>
Cc: Karsten Keil <redacted>
Signed-off-by: Kees Cook <redacted>
---
netdev doesn't like explict stable markings, so I'll just ask here that it
get included in -stable please. :)
---
 drivers/isdn/i4l/isdn_common.c | 8 +-------
 1 file changed, 1 insertion(+), 7 deletions(-)
diff --git a/drivers/isdn/i4l/isdn_common.c b/drivers/isdn/i4l/isdn_common.c
index 7a501dbe7123..6a5b3f00f9ad 100644
--- a/drivers/isdn/i4l/isdn_common.c
+++ b/drivers/isdn/i4l/isdn_common.c
@@ -1640,13 +1640,7 @@ isdn_ioctl(struct file *file, uint cmd, ulong arg)
 			} else
 				return -EINVAL;
 		case IIOCDBGVAR:
-			if (arg) {
-				if (copy_to_user(argp, &dev, sizeof(ulong)))
-					return -EFAULT;
-				return 0;
-			} else
-				return -EINVAL;
-			break;
+			return -EINVAL;
 		default:
 			if ((cmd & IIOCDRVCTL) == IIOCDRVCTL)
 				cmd = ((cmd >> _IOC_NRSHIFT) & _IOC_NRMASK) & ISDN_DRVIOCTL_MASK;
-- 
2.17.1


-- 
Kees Cook
Pixel Security

Re: [PATCH] isdn: Disable IIOCDBGVAR

From: David Miller <davem@davemloft.net>
Date: 2018-08-16 19:26:48

From: Kees Cook <redacted>
Date: Wed, 15 Aug 2018 12:14:05 -0700
It was possible to directly leak the kernel address where the isdn_dev
structure pointer was stored. This is a kernel ASLR bypass for anyone
with access to the ioctl. The code had been present since the beginning
of git history, though this shouldn't ever be needed for normal operation,
therefore remove it.

Reported-by: Al Viro <viro@zeniv.linux.org.uk>
Cc: Karsten Keil <redacted>
Signed-off-by: Kees Cook <redacted>
---
netdev doesn't like explict stable markings, so I'll just ask here that it
get included in -stable please. :)
Applied and queued up for -stable, thanks :)
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help