ce15d645be
CVE-2010-4346: install_special_mapping skips security_file_mmap check CVE-2010-4649: IB/uverbs: Handle large number of entries in poll CQ CVE-2011-0006: ima: fix add LSM rule bug CVE-2010-4648: orinoco: fix TKIP countermeasure behaviour CVE-2010-4650: fuse: verify ioctl retries
57 lines
1.5 KiB
Diff
57 lines
1.5 KiB
Diff
From: Miklos Szeredi <mszeredi@suse.cz>
|
|
Date: Tue, 30 Nov 2010 15:39:27 +0000 (+0100)
|
|
Subject: fuse: verify ioctl retries
|
|
X-Git-Tag: v2.6.37-rc6~31^2
|
|
X-Git-Url: http://git.kernel.org/?p=linux%2Fkernel%2Fgit%2Ftorvalds%2Flinux-2.6.git;a=commitdiff_plain;h=7572777eef78ebdee1ecb7c258c0ef94d35bad16
|
|
|
|
fuse: verify ioctl retries
|
|
|
|
Verify that the total length of the iovec returned in FUSE_IOCTL_RETRY
|
|
doesn't overflow iov_length().
|
|
|
|
Signed-off-by: Miklos Szeredi <mszeredi@suse.cz>
|
|
CC: Tejun Heo <tj@kernel.org>
|
|
CC: <stable@kernel.org> [2.6.31+]
|
|
---
|
|
|
|
diff --git a/fs/fuse/file.c b/fs/fuse/file.c
|
|
index 0e2e25b..8b984a2 100644
|
|
--- a/fs/fuse/file.c
|
|
+++ b/fs/fuse/file.c
|
|
@@ -1666,6 +1666,20 @@ static int fuse_copy_ioctl_iovec(struct iovec *dst, void *src,
|
|
return 0;
|
|
}
|
|
|
|
+/* Make sure iov_length() won't overflow */
|
|
+static int fuse_verify_ioctl_iov(struct iovec *iov, size_t count)
|
|
+{
|
|
+ size_t n;
|
|
+ u32 max = FUSE_MAX_PAGES_PER_REQ << PAGE_SHIFT;
|
|
+
|
|
+ for (n = 0; n < count; n++) {
|
|
+ if (iov->iov_len > (size_t) max)
|
|
+ return -ENOMEM;
|
|
+ max -= iov->iov_len;
|
|
+ }
|
|
+ return 0;
|
|
+}
|
|
+
|
|
/*
|
|
* For ioctls, there is no generic way to determine how much memory
|
|
* needs to be read and/or written. Furthermore, ioctls are allowed
|
|
@@ -1858,6 +1872,14 @@ long fuse_do_ioctl(struct file *file, unsigned int cmd, unsigned long arg,
|
|
in_iov = page_address(iov_page);
|
|
out_iov = in_iov + in_iovs;
|
|
|
|
+ err = fuse_verify_ioctl_iov(in_iov, in_iovs);
|
|
+ if (err)
|
|
+ goto out;
|
|
+
|
|
+ err = fuse_verify_ioctl_iov(out_iov, out_iovs);
|
|
+ if (err)
|
|
+ goto out;
|
|
+
|
|
goto retry;
|
|
}
|
|
|