[PATCH] net: usb: Fix uninit-was-stored issue in asix_read_phy_addr()

Subsystems: networking drivers, the rest, usb networking drivers

STALE2194d

5 messages, 4 authors, 2020-08-28 · open the first message on its own page

[PATCH] net: usb: Fix uninit-was-stored issue in asix_read_phy_addr()

From: Himadri Pandya <hidden>
Date: 2020-08-27 06:54:38

The buffer size is 2 Bytes and we expect to receive the same amount of
data. But sometimes we receive less data and run into uninit-was-stored
issue upon read. Hence modify the error check on the return value to match
with the buffer size as a prevention.

Reported-and-tested by: syzbot+a7e220df5a81d1ab400e@syzkaller.appspotmail.com
Signed-off-by: Himadri Pandya <redacted>
---
 drivers/net/usb/asix_common.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/usb/asix_common.c b/drivers/net/usb/asix_common.c
index e39f41efda3e..7bc6e8f856fe 100644
--- a/drivers/net/usb/asix_common.c
+++ b/drivers/net/usb/asix_common.c
@@ -296,7 +296,7 @@ int asix_read_phy_addr(struct usbnet *dev, int internal)
 
 	netdev_dbg(dev->net, "asix_get_phy_addr()\n");
 
-	if (ret < 0) {
+	if (ret < 2) {
 		netdev_err(dev->net, "Error reading PHYID register: %02x\n", ret);
 		goto out;
 	}
-- 
2.17.1

Re: [PATCH] net: usb: Fix uninit-was-stored issue in asix_read_phy_addr()

From: Sergei Shtylyov <hidden>
Date: 2020-08-27 07:58:57

Hello!

On 27.08.2020 9:53, Himadri Pandya wrote:
quoted hunk
The buffer size is 2 Bytes and we expect to receive the same amount of
data. But sometimes we receive less data and run into uninit-was-stored
issue upon read. Hence modify the error check on the return value to match
with the buffer size as a prevention.

Reported-and-tested by: syzbot+a7e220df5a81d1ab400e@syzkaller.appspotmail.com
Signed-off-by: Himadri Pandya <redacted>
---
  drivers/net/usb/asix_common.c | 2 +-
  1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/usb/asix_common.c b/drivers/net/usb/asix_common.c
index e39f41efda3e..7bc6e8f856fe 100644
--- a/drivers/net/usb/asix_common.c
+++ b/drivers/net/usb/asix_common.c
@@ -296,7 +296,7 @@ int asix_read_phy_addr(struct usbnet *dev, int internal)
  
  	netdev_dbg(dev->net, "asix_get_phy_addr()\n");
  
-	if (ret < 0) {
+	if (ret < 2) {
  		netdev_err(dev->net, "Error reading PHYID register: %02x\n", ret);
    Hm... printing possibly negative values as hex?

[...]

MBR, Sergei

Re: [PATCH] net: usb: Fix uninit-was-stored issue in asix_read_phy_addr()

From: David Miller <davem@davemloft.net>
Date: 2020-08-27 14:44:49

From: Himadri Pandya <redacted>
Date: Thu, 27 Aug 2020 12:23:55 +0530
The buffer size is 2 Bytes and we expect to receive the same amount of
data. But sometimes we receive less data and run into uninit-was-stored
issue upon read. Hence modify the error check on the return value to match
with the buffer size as a prevention.

Reported-and-tested by: syzbot+a7e220df5a81d1ab400e@syzkaller.appspotmail.com
Signed-off-by: Himadri Pandya <redacted>
Applied, thanks.

Re: [PATCH] net: usb: Fix uninit-was-stored issue in asix_read_phy_addr()

From: Eric Biggers <ebiggers@kernel.org>
Date: 2020-08-27 17:52:37

On Thu, Aug 27, 2020 at 12:23:55PM +0530, Himadri Pandya wrote:
quoted hunk
The buffer size is 2 Bytes and we expect to receive the same amount of
data. But sometimes we receive less data and run into uninit-was-stored
issue upon read. Hence modify the error check on the return value to match
with the buffer size as a prevention.

Reported-and-tested by: syzbot+a7e220df5a81d1ab400e@syzkaller.appspotmail.com
Signed-off-by: Himadri Pandya <redacted>
---
 drivers/net/usb/asix_common.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/usb/asix_common.c b/drivers/net/usb/asix_common.c
index e39f41efda3e..7bc6e8f856fe 100644
--- a/drivers/net/usb/asix_common.c
+++ b/drivers/net/usb/asix_common.c
@@ -296,7 +296,7 @@ int asix_read_phy_addr(struct usbnet *dev, int internal)
 
 	netdev_dbg(dev->net, "asix_get_phy_addr()\n");
 
-	if (ret < 0) {
+	if (ret < 2) {
 		netdev_err(dev->net, "Error reading PHYID register: %02x\n", ret);
 		goto out;
 	}
If ret is 0 or 1 here, shouldn't asix_read_phy_addr() return an error code
instead of 0 or 1?

- Eric

Re: [PATCH] net: usb: Fix uninit-was-stored issue in asix_read_phy_addr()

From: Himadri Pandya <hidden>
Date: 2020-08-28 11:11:03

On Thu, Aug 27, 2020 at 1:28 PM Sergei Shtylyov
[off-list ref] wrote:
Hello!

On 27.08.2020 9:53, Himadri Pandya wrote:
quoted
The buffer size is 2 Bytes and we expect to receive the same amount of
data. But sometimes we receive less data and run into uninit-was-stored
issue upon read. Hence modify the error check on the return value to match
with the buffer size as a prevention.

Reported-and-tested by: syzbot+a7e220df5a81d1ab400e@syzkaller.appspotmail.com
Signed-off-by: Himadri Pandya <redacted>
---
  drivers/net/usb/asix_common.c | 2 +-
  1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/usb/asix_common.c b/drivers/net/usb/asix_common.c
index e39f41efda3e..7bc6e8f856fe 100644
--- a/drivers/net/usb/asix_common.c
+++ b/drivers/net/usb/asix_common.c
@@ -296,7 +296,7 @@ int asix_read_phy_addr(struct usbnet *dev, int internal)

      netdev_dbg(dev->net, "asix_get_phy_addr()\n");

-     if (ret < 0) {
+     if (ret < 2) {
              netdev_err(dev->net, "Error reading PHYID register: %02x\n", ret);
    Hm... printing possibly negative values as hex?
Yeah. That's odd! Fixing it.

Thanks,
Himadri
[...]

MBR, Sergei
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help