mirror of
https://github.com/torvalds/linux.git
synced 2026-09-24 06:24:02 +02:00
usb: gadget: configfs: fix out-of-bounds read of qw_sign
os_desc_qw_sign_show() passes OS_STRING_QW_SIGN_LEN as the input
length to utf16s_to_utf8s(), but that argument counts UTF-16 code
units while OS_STRING_QW_SIGN_LEN (14) is the byte size of qw_sign[].
The array holds only OS_STRING_QW_SIGN_LEN / 2 (7) code units, so the
conversion reads up to 7 units (14 bytes) past the end of qw_sign[]
into the following members of struct gadget_info when the stored
signature fills the array without a NUL terminator, exposing those
bytes through the configfs attribute.
The store path halves the count for its input bound but passes the
full byte count as the utf8s_to_utf16s() output limit; use the
destination code-unit count in both directions.
Fixes: 76180d716f ("usb: gadget: configfs: make qw_sign attribute symmetric")
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com>
Link: https://patch.msgid.link/20260618005043.1581707-1-michael.bommarito@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
This commit is contained in:
parent
057df423bf
commit
f63edb54d8
|
|
@ -1177,7 +1177,7 @@ static ssize_t os_desc_qw_sign_show(struct config_item *item, char *page)
|
|||
struct gadget_info *gi = os_desc_item_to_gadget_info(item);
|
||||
int res;
|
||||
|
||||
res = utf16s_to_utf8s((wchar_t *) gi->qw_sign, OS_STRING_QW_SIGN_LEN,
|
||||
res = utf16s_to_utf8s((wchar_t *) gi->qw_sign, OS_STRING_QW_SIGN_LEN / 2,
|
||||
UTF16_LITTLE_ENDIAN, page, PAGE_SIZE - 1);
|
||||
page[res++] = '\n';
|
||||
|
||||
|
|
@ -1199,7 +1199,7 @@ static ssize_t os_desc_qw_sign_store(struct config_item *item, const char *page,
|
|||
mutex_lock(&gi->lock);
|
||||
res = utf8s_to_utf16s(page, l,
|
||||
UTF16_LITTLE_ENDIAN, (wchar_t *) gi->qw_sign,
|
||||
OS_STRING_QW_SIGN_LEN);
|
||||
OS_STRING_QW_SIGN_LEN / 2);
|
||||
if (res > 0)
|
||||
res = len;
|
||||
mutex_unlock(&gi->lock);
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user