Netdev Archive on lore.kernel.org
 help / color / Atom feed
* [PATCH] r8152: add missing endpoint sanity check
@ 2020-01-14  8:27 Johan Hovold
  2020-01-15  2:44 ` David Miller
  0 siblings, 1 reply; 2+ messages in thread
From: Johan Hovold @ 2020-01-14  8:27 UTC (permalink / raw)
  To: netdev; +Cc: linux-usb, linux-kernel, Johan Hovold, hayeswang

Add missing endpoint sanity check to probe in order to prevent a
NULL-pointer dereference (or slab out-of-bounds access) when retrieving
the interrupt-endpoint bInterval on ndo_open() in case a device lacks
the expected endpoints.

Fixes: 40a82917b1d3 ("net/usb/r8152: enable interrupt transfer")
Cc: hayeswang <hayeswang@realtek.com>
Signed-off-by: Johan Hovold <johan@kernel.org>
---
 drivers/net/usb/r8152.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/drivers/net/usb/r8152.c b/drivers/net/usb/r8152.c
index c5ebf35d2488..031cb8fff909 100644
--- a/drivers/net/usb/r8152.c
+++ b/drivers/net/usb/r8152.c
@@ -6597,6 +6597,9 @@ static int rtl8152_probe(struct usb_interface *intf,
 		return -ENODEV;
 	}
 
+	if (intf->cur_altsetting->desc.bNumEndpoints < 3)
+		return -ENODEV;
+
 	usb_reset_device(udev);
 	netdev = alloc_etherdev(sizeof(struct r8152));
 	if (!netdev) {
-- 
2.24.1


^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: [PATCH] r8152: add missing endpoint sanity check
  2020-01-14  8:27 [PATCH] r8152: add missing endpoint sanity check Johan Hovold
@ 2020-01-15  2:44 ` David Miller
  0 siblings, 0 replies; 2+ messages in thread
From: David Miller @ 2020-01-15  2:44 UTC (permalink / raw)
  To: johan; +Cc: netdev, linux-usb, linux-kernel, hayeswang

From: Johan Hovold <johan@kernel.org>
Date: Tue, 14 Jan 2020 09:27:29 +0100

> Add missing endpoint sanity check to probe in order to prevent a
> NULL-pointer dereference (or slab out-of-bounds access) when retrieving
> the interrupt-endpoint bInterval on ndo_open() in case a device lacks
> the expected endpoints.
> 
> Fixes: 40a82917b1d3 ("net/usb/r8152: enable interrupt transfer")
> Cc: hayeswang <hayeswang@realtek.com>
> Signed-off-by: Johan Hovold <johan@kernel.org>

Applied and queued up for -stable, thank you.

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, back to index

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2020-01-14  8:27 [PATCH] r8152: add missing endpoint sanity check Johan Hovold
2020-01-15  2:44 ` David Miller

Netdev Archive on lore.kernel.org

Archives are clonable:
	git clone --mirror https://lore.kernel.org/netdev/0 netdev/git/0.git
	git clone --mirror https://lore.kernel.org/netdev/1 netdev/git/1.git

	# If you have public-inbox 1.1+ installed, you may
	# initialize and index your mirror using the following commands:
	public-inbox-init -V2 netdev netdev/ https://lore.kernel.org/netdev \
		netdev@vger.kernel.org
	public-inbox-index netdev

Example config snippet for mirrors

Newsgroup available over NNTP:
	nntp://nntp.lore.kernel.org/org.kernel.vger.netdev


AGPL code for this site: git clone https://public-inbox.org/public-inbox.git