[wily/master-next 1/7] staging/dgnc: fix info leak in ioctl

Andy Whitcroft apw at canonical.com
Wed Dec 2 14:59:31 UTC 2015


From: Salva Peiró <speirofr at gmail.com>

The dgnc_mgmt_ioctl() code fails to initialize the 16 _reserved bytes of
struct digi_dinfo after the ->dinfo_nboards member. Add an explicit
memset(0) before filling the structure to avoid the info leak.

Signed-off-by: Salva Peiró <speirofr at gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh at linuxfoundation.org>

(cherry picked from commit 4b6184336ebb5c8dc1eae7f7ab46ee608a748b05)
CVE-2015-7885
BugLink: http://bugs.launchpad.net/bugs/1509565
Signed-off-by: Andy Whitcroft <apw at canonical.com>
---
 drivers/staging/dgnc/dgnc_mgmt.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/staging/dgnc/dgnc_mgmt.c b/drivers/staging/dgnc/dgnc_mgmt.c
index b13318a..883e2a8 100644
--- a/drivers/staging/dgnc/dgnc_mgmt.c
+++ b/drivers/staging/dgnc/dgnc_mgmt.c
@@ -115,6 +115,7 @@ long dgnc_mgmt_ioctl(struct file *file, unsigned int cmd, unsigned long arg)
 
 		spin_lock_irqsave(&dgnc_global_lock, flags);
 
+		memset(&ddi, 0, sizeof(ddi));
 		ddi.dinfo_nboards = dgnc_NumBoards;
 		sprintf(ddi.dinfo_version, "%s", DG_PART);
 
-- 
2.6.2





More information about the kernel-team mailing list