mirror of
https://github.com/torvalds/linux.git
synced 2026-07-27 09:36:22 +02:00
USB/Thunderbolt fixes for 7.1-final
Here are some small bugfixes for USB serial and Thunderbolt drivers for some reported and found issues. Included in here are: - usb serial overflow bugs fixed - new usb serial device id - thunderbolt validation fixes for reported issues All of these have been in linux-next this week with no reported issues. Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> -----BEGIN PGP SIGNATURE----- iG0EABECAC0WIQT0tgzFv3jCIUoxPcsxR9QN2y37KQUCaivU8w8cZ3JlZ0Brcm9h aC5jb20ACgkQMUfUDdst+ylkDQCgl/tr857mpCkfWSX+GxFnp5BJhqYAn26ISsqK HujT9oSMn1j9W4iR3PEm =4zy7 -----END PGP SIGNATURE----- Merge tag 'usb-7.1-final' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/usb Pull USB / Thunderbolt fixes from Greg KH: "Here are some small bugfixes for USB serial and Thunderbolt drivers for some reported and found issues. Included in here are: - usb serial overflow bugs fixed - new usb serial device id - thunderbolt validation fixes for reported issues All of these have been in linux-next this week with no reported issues" * tag 'usb-7.1-final' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/usb: USB: serial: kl5kusb105: fix bulk-out buffer overflow USB: serial: option: add usb-id for Dell Wireless DW5826e-m USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() USB: serial: io_ti: fix heap overflow in get_manuf_info() thunderbolt: Limit XDomain response copy to actual frame size thunderbolt: Validate XDomain request packet size before type cast thunderbolt: Clamp XDomain response data copy to allocation size thunderbolt: Bound root directory content to block size thunderbolt: Reject zero-length property entries in validator
This commit is contained in:
commit
2e04e0961e
|
|
@ -60,6 +60,8 @@ static bool tb_property_entry_valid(const struct tb_property_entry *entry,
|
|||
case TB_PROPERTY_TYPE_DIRECTORY:
|
||||
case TB_PROPERTY_TYPE_DATA:
|
||||
case TB_PROPERTY_TYPE_TEXT:
|
||||
if (!entry->length)
|
||||
return false;
|
||||
if (entry->length > block_len)
|
||||
return false;
|
||||
if (check_add_overflow(entry->value, entry->length, &end) ||
|
||||
|
|
@ -185,6 +187,10 @@ static struct tb_property_dir *__tb_property_parse_dir(const u32 *block,
|
|||
if (is_root) {
|
||||
content_offset = dir_offset + 2;
|
||||
content_len = dir_len;
|
||||
if (content_offset + content_len > block_len) {
|
||||
tb_property_free_dir(dir);
|
||||
return NULL;
|
||||
}
|
||||
} else {
|
||||
if (dir_len < 4) {
|
||||
tb_property_free_dir(dir);
|
||||
|
|
|
|||
|
|
@ -55,6 +55,7 @@ static const char * const state_names[] = {
|
|||
struct xdomain_request_work {
|
||||
struct work_struct work;
|
||||
struct tb_xdp_header *pkg;
|
||||
size_t pkg_len;
|
||||
struct tb *tb;
|
||||
};
|
||||
|
||||
|
|
@ -122,7 +123,9 @@ static bool tb_xdomain_match(const struct tb_cfg_request *req,
|
|||
static bool tb_xdomain_copy(struct tb_cfg_request *req,
|
||||
const struct ctl_pkg *pkg)
|
||||
{
|
||||
memcpy(req->response, pkg->buffer, req->response_size);
|
||||
size_t len = min_t(size_t, pkg->frame.size, req->response_size);
|
||||
|
||||
memcpy(req->response, pkg->buffer, len);
|
||||
req->result.err = 0;
|
||||
return true;
|
||||
}
|
||||
|
|
@ -393,6 +396,8 @@ static int tb_xdp_properties_request(struct tb_ctl *ctl, u64 route,
|
|||
}
|
||||
}
|
||||
|
||||
if (req.offset + len > data_len)
|
||||
len = data_len - req.offset;
|
||||
memcpy(data + req.offset, res->data, len * 4);
|
||||
req.offset += len;
|
||||
} while (!data_len || req.offset < data_len);
|
||||
|
|
@ -731,6 +736,7 @@ static void tb_xdp_handle_request(struct work_struct *work)
|
|||
struct xdomain_request_work *xw = container_of(work, typeof(*xw), work);
|
||||
const struct tb_xdp_header *pkg = xw->pkg;
|
||||
const struct tb_xdomain_header *xhdr = &pkg->xd_hdr;
|
||||
size_t pkg_len = xw->pkg_len;
|
||||
struct tb *tb = xw->tb;
|
||||
struct tb_ctl *ctl = tb->ctl;
|
||||
struct tb_xdomain *xd;
|
||||
|
|
@ -762,7 +768,7 @@ static void tb_xdp_handle_request(struct work_struct *work)
|
|||
switch (pkg->type) {
|
||||
case PROPERTIES_REQUEST:
|
||||
tb_dbg(tb, "%llx: received XDomain properties request\n", route);
|
||||
if (xd) {
|
||||
if (xd && pkg_len >= sizeof(struct tb_xdp_properties)) {
|
||||
ret = tb_xdp_properties_response(tb, ctl, xd, sequence,
|
||||
(const struct tb_xdp_properties *)pkg);
|
||||
}
|
||||
|
|
@ -816,7 +822,8 @@ static void tb_xdp_handle_request(struct work_struct *work)
|
|||
tb_dbg(tb, "%llx: received XDomain link state change request\n",
|
||||
route);
|
||||
|
||||
if (xd && xd->state == XDOMAIN_STATE_BONDING_UUID_HIGH) {
|
||||
if (xd && xd->state == XDOMAIN_STATE_BONDING_UUID_HIGH &&
|
||||
pkg_len >= sizeof(struct tb_xdp_link_state_change)) {
|
||||
const struct tb_xdp_link_state_change *lsc =
|
||||
(const struct tb_xdp_link_state_change *)pkg;
|
||||
|
||||
|
|
@ -868,6 +875,7 @@ tb_xdp_schedule_request(struct tb *tb, const struct tb_xdp_header *hdr,
|
|||
kfree(xw);
|
||||
return false;
|
||||
}
|
||||
xw->pkg_len = size;
|
||||
xw->tb = tb_domain_get(tb);
|
||||
|
||||
schedule_work(&xw->work);
|
||||
|
|
|
|||
|
|
@ -773,6 +773,12 @@ static int get_manuf_info(struct edgeport_serial *serial, u8 *buffer)
|
|||
}
|
||||
|
||||
/* Read the descriptor data */
|
||||
if (le16_to_cpu(rom_desc->Size) != sizeof(struct edge_ti_manuf_descriptor)) {
|
||||
dev_err(dev, "unexpected Edge descriptor length: %u\n",
|
||||
le16_to_cpu(rom_desc->Size));
|
||||
status = -EINVAL;
|
||||
goto exit;
|
||||
}
|
||||
status = read_rom(serial, start_address+sizeof(struct ti_i2c_desc),
|
||||
le16_to_cpu(rom_desc->Size), buffer);
|
||||
if (status)
|
||||
|
|
@ -838,6 +844,11 @@ static int build_i2c_fw_hdr(u8 *header, const struct firmware *fw)
|
|||
/* Pointer to fw_down memory image */
|
||||
img_header = (struct ti_i2c_image_header *)&fw->data[4];
|
||||
|
||||
if (le16_to_cpu(img_header->Length) >
|
||||
buffer_size - sizeof(struct ti_i2c_firmware_rec)) {
|
||||
kfree(buffer);
|
||||
return -EINVAL;
|
||||
}
|
||||
memcpy(buffer + sizeof(struct ti_i2c_firmware_rec),
|
||||
&fw->data[4 + sizeof(struct ti_i2c_image_header)],
|
||||
le16_to_cpu(img_header->Length));
|
||||
|
|
|
|||
|
|
@ -330,8 +330,8 @@ static int klsi_105_prepare_write_buffer(struct usb_serial_port *port,
|
|||
unsigned char *buf = dest;
|
||||
int count;
|
||||
|
||||
count = kfifo_out_locked(&port->write_fifo, buf + KLSI_HDR_LEN, size,
|
||||
&port->lock);
|
||||
count = kfifo_out_locked(&port->write_fifo, buf + KLSI_HDR_LEN,
|
||||
size - KLSI_HDR_LEN, &port->lock);
|
||||
put_unaligned_le16(count, buf);
|
||||
|
||||
return count + KLSI_HDR_LEN;
|
||||
|
|
|
|||
|
|
@ -202,6 +202,7 @@ static void option_instat_callback(struct urb *urb);
|
|||
#define DELL_PRODUCT_5821E_ESIM 0x81e0
|
||||
#define DELL_PRODUCT_5829E_ESIM 0x81e4
|
||||
#define DELL_PRODUCT_5829E 0x81e6
|
||||
#define DELL_PRODUCT_5826E_ESIM 0x81ea
|
||||
|
||||
#define DELL_PRODUCT_FM101R_ESIM 0x8213
|
||||
#define DELL_PRODUCT_FM101R 0x8215
|
||||
|
|
@ -1123,6 +1124,8 @@ static const struct usb_device_id option_ids[] = {
|
|||
.driver_info = RSVD(0) | RSVD(6) },
|
||||
{ USB_DEVICE(DELL_VENDOR_ID, DELL_PRODUCT_5829E_ESIM),
|
||||
.driver_info = RSVD(0) | RSVD(6) },
|
||||
{ USB_DEVICE_INTERFACE_CLASS(DELL_VENDOR_ID, DELL_PRODUCT_5826E_ESIM, 0xff),
|
||||
.driver_info = RSVD(1) | RSVD(4) },
|
||||
{ USB_DEVICE_INTERFACE_CLASS(DELL_VENDOR_ID, DELL_PRODUCT_FM101R, 0xff) },
|
||||
{ USB_DEVICE_INTERFACE_CLASS(DELL_VENDOR_ID, DELL_PRODUCT_FM101R_ESIM, 0xff) },
|
||||
{ USB_DEVICE(ANYDATA_VENDOR_ID, ANYDATA_PRODUCT_ADU_E100A) }, /* ADU-E100, ADU-310 */
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user