43 lines
1.6 KiB
Diff
43 lines
1.6 KiB
Diff
From: Wu Bo <wubo40@huawei.com>
|
|
Date: Tue, 14 Apr 2020 10:13:28 +0800
|
|
Subject: scsi: sg: add sg_remove_request in sg_write
|
|
Origin: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable.git/commit?id=34fcb4291e234468f9bf9d4b851c9f522f3bbb13
|
|
Bug-Debian-Security: https://security-tracker.debian.org/tracker/CVE-2020-12770
|
|
|
|
commit 83c6f2390040f188cc25b270b4befeb5628c1aee upstream.
|
|
|
|
If the __copy_from_user function failed we need to call sg_remove_request
|
|
in sg_write.
|
|
|
|
Link: https://lore.kernel.org/r/610618d9-e983-fd56-ed0f-639428343af7@huawei.com
|
|
Acked-by: Douglas Gilbert <dgilbert@interlog.com>
|
|
Signed-off-by: Wu Bo <wubo40@huawei.com>
|
|
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
|
|
Signed-off-by: Sasha Levin <sashal@kernel.org>
|
|
[groeck: Backport to v5.4.y and older kernels]
|
|
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
|
|
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
|
|
---
|
|
drivers/scsi/sg.c | 4 +++-
|
|
1 file changed, 3 insertions(+), 1 deletion(-)
|
|
|
|
diff --git a/drivers/scsi/sg.c b/drivers/scsi/sg.c
|
|
index ac8535d2b41a..6bb45ae19d58 100644
|
|
--- a/drivers/scsi/sg.c
|
|
+++ b/drivers/scsi/sg.c
|
|
@@ -694,8 +694,10 @@ sg_write(struct file *filp, const char __user *buf, size_t count, loff_t * ppos)
|
|
hp->flags = input_size; /* structure abuse ... */
|
|
hp->pack_id = old_hdr.pack_id;
|
|
hp->usr_ptr = NULL;
|
|
- if (__copy_from_user(cmnd, buf, cmd_size))
|
|
+ if (__copy_from_user(cmnd, buf, cmd_size)) {
|
|
+ sg_remove_request(sfp, srp);
|
|
return -EFAULT;
|
|
+ }
|
|
/*
|
|
* SG_DXFER_TO_FROM_DEV is functionally equivalent to SG_DXFER_FROM_DEV,
|
|
* but is is possible that the app intended SG_DXFER_TO_DEV, because there
|
|
--
|
|
2.27.0.rc0
|
|
|