* [PATCH 4.14 1/1] can: usb_8dev: usb_8dev_start_xmit(): fix double dev_kfree_skb() in error path
2022-04-19 11:38 [PATCH 4.14 0/1] can: usb_8dev: backport fix for CVE-2022-28388 Dragos-Marian Panait
@ 2022-04-19 11:38 ` Dragos-Marian Panait
2022-04-21 9:55 ` [PATCH 4.14 0/1] can: usb_8dev: backport fix for CVE-2022-28388 Greg KH
1 sibling, 0 replies; 3+ messages in thread
From: Dragos-Marian Panait @ 2022-04-19 11:38 UTC (permalink / raw)
To: stable
Cc: dragos.panait, wg, mkl, davem, paskripkin, gregkh, hbh25y,
linux-can, netdev, linux-kernel
From: Hangyu Hua <hbh25y@gmail.com>
commit 3d3925ff6433f98992685a9679613a2cc97f3ce2 upstream.
There is no need to call dev_kfree_skb() when usb_submit_urb() fails
because can_put_echo_skb() deletes original skb and
can_free_echo_skb() deletes the cloned skb.
Fixes: 0024d8ad1639 ("can: usb_8dev: Add support for USB2CAN interface from 8 devices")
Link: https://lore.kernel.org/all/20220311080614.45229-1-hbh25y@gmail.com
Cc: stable@vger.kernel.org
Signed-off-by: Hangyu Hua <hbh25y@gmail.com>
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
[DP: adjusted params of can_free_echo_skb() for 4.14 stable]
Signed-off-by: Dragos-Marian Panait <dragos.panait@windriver.com>
---
drivers/net/can/usb/usb_8dev.c | 30 ++++++++++++++----------------
1 file changed, 14 insertions(+), 16 deletions(-)
diff --git a/drivers/net/can/usb/usb_8dev.c b/drivers/net/can/usb/usb_8dev.c
index df99354ec12a..232f45f722f0 100644
--- a/drivers/net/can/usb/usb_8dev.c
+++ b/drivers/net/can/usb/usb_8dev.c
@@ -681,9 +681,20 @@ static netdev_tx_t usb_8dev_start_xmit(struct sk_buff *skb,
atomic_inc(&priv->active_tx_urbs);
err = usb_submit_urb(urb, GFP_ATOMIC);
- if (unlikely(err))
- goto failed;
- else if (atomic_read(&priv->active_tx_urbs) >= MAX_TX_URBS)
+ if (unlikely(err)) {
+ can_free_echo_skb(netdev, context->echo_index);
+
+ usb_unanchor_urb(urb);
+ usb_free_coherent(priv->udev, size, buf, urb->transfer_dma);
+
+ atomic_dec(&priv->active_tx_urbs);
+
+ if (err == -ENODEV)
+ netif_device_detach(netdev);
+ else
+ netdev_warn(netdev, "failed tx_urb %d\n", err);
+ stats->tx_dropped++;
+ } else if (atomic_read(&priv->active_tx_urbs) >= MAX_TX_URBS)
/* Slow down tx path */
netif_stop_queue(netdev);
@@ -702,19 +713,6 @@ static netdev_tx_t usb_8dev_start_xmit(struct sk_buff *skb,
return NETDEV_TX_BUSY;
-failed:
- can_free_echo_skb(netdev, context->echo_index);
-
- usb_unanchor_urb(urb);
- usb_free_coherent(priv->udev, size, buf, urb->transfer_dma);
-
- atomic_dec(&priv->active_tx_urbs);
-
- if (err == -ENODEV)
- netif_device_detach(netdev);
- else
- netdev_warn(netdev, "failed tx_urb %d\n", err);
-
nomembuf:
usb_free_urb(urb);
--
2.17.1
^ permalink raw reply related [flat|nested] 3+ messages in thread
* Re: [PATCH 4.14 0/1] can: usb_8dev: backport fix for CVE-2022-28388
2022-04-19 11:38 [PATCH 4.14 0/1] can: usb_8dev: backport fix for CVE-2022-28388 Dragos-Marian Panait
2022-04-19 11:38 ` [PATCH 4.14 1/1] can: usb_8dev: usb_8dev_start_xmit(): fix double dev_kfree_skb() in error path Dragos-Marian Panait
@ 2022-04-21 9:55 ` Greg KH
1 sibling, 0 replies; 3+ messages in thread
From: Greg KH @ 2022-04-21 9:55 UTC (permalink / raw)
To: Dragos-Marian Panait
Cc: stable, wg, mkl, davem, paskripkin, hbh25y, linux-can, netdev,
linux-kernel
On Tue, Apr 19, 2022 at 02:38:33PM +0300, Dragos-Marian Panait wrote:
> The following commit is needed to fix CVE-2022-28388:
> https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=3d3925ff6433f98992685a9679613a2cc97f3ce2
>
> Hangyu Hua (1):
> can: usb_8dev: usb_8dev_start_xmit(): fix double dev_kfree_skb() in
> error path
>
> drivers/net/can/usb/usb_8dev.c | 30 ++++++++++++++----------------
> 1 file changed, 14 insertions(+), 16 deletions(-)
>
>
> base-commit: 74766a973637a02c32c04c1c6496e114e4855239
> --
> 2.17.1
>
All now queued up, thanks.
greg k-h
^ permalink raw reply [flat|nested] 3+ messages in thread