All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH 1/3] ath10k: fix division by zero in send path
@ 2021-10-26  9:52 Johan Hovold
  2021-10-26  9:52 ` [PATCH 2/3] ath6kl: " Johan Hovold
  2021-10-26  9:52 ` [PATCH 3/3] mwifiex: fix division by zero in fw download path Johan Hovold
  0 siblings, 2 replies; 6+ messages in thread
From: Johan Hovold @ 2021-10-26  9:52 UTC (permalink / raw)
  To: Kalle Valo
  Cc: Amitkumar Karwar, Ganapathi Bhat, Sharvari Harisangam,
	Xinming Hu, linux-wireless, netdev, linux-usb, linux-kernel,
	Johan Hovold, stable, Erik Stromdahl

Add the missing endpoint max-packet sanity check to probe() to avoid
division by zero in ath10k_usb_hif_tx_sg() in case a malicious device
has broken descriptors (or when doing descriptor fuzz testing).

Note that USB core will reject URBs submitted for endpoints with zero
wMaxPacketSize but that drivers doing packet-size calculations still
need to handle this (cf. commit 2548288b4fb0 ("USB: Fix: Don't skip
endpoint descriptors with maxpacket=0")).

Fixes: 4db66499df91 ("ath10k: add initial USB support")
Cc: stable@vger.kernel.org      # 4.14
Cc: Erik Stromdahl <erik.stromdahl@gmail.com>
Signed-off-by: Johan Hovold <johan@kernel.org>
---
 drivers/net/wireless/ath/ath10k/usb.c | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/drivers/net/wireless/ath/ath10k/usb.c b/drivers/net/wireless/ath/ath10k/usb.c
index 6d831b098cbb..3d98f19c6ec8 100644
--- a/drivers/net/wireless/ath/ath10k/usb.c
+++ b/drivers/net/wireless/ath/ath10k/usb.c
@@ -853,6 +853,11 @@ static int ath10k_usb_setup_pipe_resources(struct ath10k *ar,
 				   le16_to_cpu(endpoint->wMaxPacketSize),
 				   endpoint->bInterval);
 		}
+
+		/* Ignore broken descriptors. */
+		if (usb_endpoint_maxp(endpoint) == 0)
+			continue;
+
 		urbcount = 0;
 
 		pipe_num =
-- 
2.32.0


^ permalink raw reply related	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2021-10-27 18:23 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2021-10-26  9:52 [PATCH 1/3] ath10k: fix division by zero in send path Johan Hovold
2021-10-26  9:52 ` [PATCH 2/3] ath6kl: " Johan Hovold
2021-10-26  9:52 ` [PATCH 3/3] mwifiex: fix division by zero in fw download path Johan Hovold
2021-10-26 17:35   ` Brian Norris
2021-10-27  7:40     ` Johan Hovold
2021-10-27 18:23       ` Brian Norris

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.