All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH 4.14 0/1] can: usb_8dev: backport fix for CVE-2022-28388
@ 2022-04-19 11:38 Dragos-Marian Panait
  2022-04-19 11:38 ` [PATCH 4.14 1/1] can: usb_8dev: usb_8dev_start_xmit(): fix double dev_kfree_skb() in error path Dragos-Marian Panait
  2022-04-21  9:55 ` [PATCH 4.14 0/1] can: usb_8dev: backport fix for CVE-2022-28388 Greg KH
  0 siblings, 2 replies; 3+ messages in thread
From: Dragos-Marian Panait @ 2022-04-19 11:38 UTC (permalink / raw)
  To: stable
  Cc: dragos.panait, wg, mkl, davem, paskripkin, gregkh, hbh25y,
	linux-can, netdev, linux-kernel

The following commit is needed to fix CVE-2022-28388:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=3d3925ff6433f98992685a9679613a2cc97f3ce2

Hangyu Hua (1):
  can: usb_8dev: usb_8dev_start_xmit(): fix double dev_kfree_skb() in
    error path

 drivers/net/can/usb/usb_8dev.c | 30 ++++++++++++++----------------
 1 file changed, 14 insertions(+), 16 deletions(-)


base-commit: 74766a973637a02c32c04c1c6496e114e4855239
-- 
2.17.1


^ permalink raw reply	[flat|nested] 3+ messages in thread

* [PATCH 4.14 1/1] can: usb_8dev: usb_8dev_start_xmit(): fix double dev_kfree_skb() in error path
  2022-04-19 11:38 [PATCH 4.14 0/1] can: usb_8dev: backport fix for CVE-2022-28388 Dragos-Marian Panait
@ 2022-04-19 11:38 ` Dragos-Marian Panait
  2022-04-21  9:55 ` [PATCH 4.14 0/1] can: usb_8dev: backport fix for CVE-2022-28388 Greg KH
  1 sibling, 0 replies; 3+ messages in thread
From: Dragos-Marian Panait @ 2022-04-19 11:38 UTC (permalink / raw)
  To: stable
  Cc: dragos.panait, wg, mkl, davem, paskripkin, gregkh, hbh25y,
	linux-can, netdev, linux-kernel

From: Hangyu Hua <hbh25y@gmail.com>

commit 3d3925ff6433f98992685a9679613a2cc97f3ce2 upstream.

There is no need to call dev_kfree_skb() when usb_submit_urb() fails
because can_put_echo_skb() deletes original skb and
can_free_echo_skb() deletes the cloned skb.

Fixes: 0024d8ad1639 ("can: usb_8dev: Add support for USB2CAN interface from 8 devices")
Link: https://lore.kernel.org/all/20220311080614.45229-1-hbh25y@gmail.com
Cc: stable@vger.kernel.org
Signed-off-by: Hangyu Hua <hbh25y@gmail.com>
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
[DP: adjusted params of can_free_echo_skb() for 4.14 stable]
Signed-off-by: Dragos-Marian Panait <dragos.panait@windriver.com>
---
 drivers/net/can/usb/usb_8dev.c | 30 ++++++++++++++----------------
 1 file changed, 14 insertions(+), 16 deletions(-)

diff --git a/drivers/net/can/usb/usb_8dev.c b/drivers/net/can/usb/usb_8dev.c
index df99354ec12a..232f45f722f0 100644
--- a/drivers/net/can/usb/usb_8dev.c
+++ b/drivers/net/can/usb/usb_8dev.c
@@ -681,9 +681,20 @@ static netdev_tx_t usb_8dev_start_xmit(struct sk_buff *skb,
 	atomic_inc(&priv->active_tx_urbs);
 
 	err = usb_submit_urb(urb, GFP_ATOMIC);
-	if (unlikely(err))
-		goto failed;
-	else if (atomic_read(&priv->active_tx_urbs) >= MAX_TX_URBS)
+	if (unlikely(err)) {
+		can_free_echo_skb(netdev, context->echo_index);
+
+		usb_unanchor_urb(urb);
+		usb_free_coherent(priv->udev, size, buf, urb->transfer_dma);
+
+		atomic_dec(&priv->active_tx_urbs);
+
+		if (err == -ENODEV)
+			netif_device_detach(netdev);
+		else
+			netdev_warn(netdev, "failed tx_urb %d\n", err);
+		stats->tx_dropped++;
+	} else if (atomic_read(&priv->active_tx_urbs) >= MAX_TX_URBS)
 		/* Slow down tx path */
 		netif_stop_queue(netdev);
 
@@ -702,19 +713,6 @@ static netdev_tx_t usb_8dev_start_xmit(struct sk_buff *skb,
 
 	return NETDEV_TX_BUSY;
 
-failed:
-	can_free_echo_skb(netdev, context->echo_index);
-
-	usb_unanchor_urb(urb);
-	usb_free_coherent(priv->udev, size, buf, urb->transfer_dma);
-
-	atomic_dec(&priv->active_tx_urbs);
-
-	if (err == -ENODEV)
-		netif_device_detach(netdev);
-	else
-		netdev_warn(netdev, "failed tx_urb %d\n", err);
-
 nomembuf:
 	usb_free_urb(urb);
 
-- 
2.17.1


^ permalink raw reply related	[flat|nested] 3+ messages in thread

* Re: [PATCH 4.14 0/1] can: usb_8dev: backport fix for CVE-2022-28388
  2022-04-19 11:38 [PATCH 4.14 0/1] can: usb_8dev: backport fix for CVE-2022-28388 Dragos-Marian Panait
  2022-04-19 11:38 ` [PATCH 4.14 1/1] can: usb_8dev: usb_8dev_start_xmit(): fix double dev_kfree_skb() in error path Dragos-Marian Panait
@ 2022-04-21  9:55 ` Greg KH
  1 sibling, 0 replies; 3+ messages in thread
From: Greg KH @ 2022-04-21  9:55 UTC (permalink / raw)
  To: Dragos-Marian Panait
  Cc: stable, wg, mkl, davem, paskripkin, hbh25y, linux-can, netdev,
	linux-kernel

On Tue, Apr 19, 2022 at 02:38:33PM +0300, Dragos-Marian Panait wrote:
> The following commit is needed to fix CVE-2022-28388:
> https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=3d3925ff6433f98992685a9679613a2cc97f3ce2
> 
> Hangyu Hua (1):
>   can: usb_8dev: usb_8dev_start_xmit(): fix double dev_kfree_skb() in
>     error path
> 
>  drivers/net/can/usb/usb_8dev.c | 30 ++++++++++++++----------------
>  1 file changed, 14 insertions(+), 16 deletions(-)
> 
> 
> base-commit: 74766a973637a02c32c04c1c6496e114e4855239
> -- 
> 2.17.1
> 

All now queued up, thanks.

greg k-h

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2022-04-21  9:55 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2022-04-19 11:38 [PATCH 4.14 0/1] can: usb_8dev: backport fix for CVE-2022-28388 Dragos-Marian Panait
2022-04-19 11:38 ` [PATCH 4.14 1/1] can: usb_8dev: usb_8dev_start_xmit(): fix double dev_kfree_skb() in error path Dragos-Marian Panait
2022-04-21  9:55 ` [PATCH 4.14 0/1] can: usb_8dev: backport fix for CVE-2022-28388 Greg KH

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.