From patchwork Fri Apr 25 14:58:39 2014 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: tim.gore@intel.com X-Patchwork-Id: 4063791 Return-Path: X-Original-To: patchwork-intel-gfx@patchwork.kernel.org Delivered-To: patchwork-parsemail@patchwork1.web.kernel.org Received: from mail.kernel.org (mail.kernel.org [198.145.19.201]) by patchwork1.web.kernel.org (Postfix) with ESMTP id D76979F38E for ; Fri, 25 Apr 2014 14:58:49 +0000 (UTC) Received: from mail.kernel.org (localhost [127.0.0.1]) by mail.kernel.org (Postfix) with ESMTP id 1B8602038C for ; Fri, 25 Apr 2014 14:58:49 +0000 (UTC) Received: from gabe.freedesktop.org (gabe.freedesktop.org [131.252.210.177]) by mail.kernel.org (Postfix) with ESMTP id 472202037A for ; Fri, 25 Apr 2014 14:58:48 +0000 (UTC) Received: from gabe.freedesktop.org (localhost [127.0.0.1]) by gabe.freedesktop.org (Postfix) with ESMTP id 2DE116EED4; Fri, 25 Apr 2014 07:58:47 -0700 (PDT) X-Original-To: intel-gfx@lists.freedesktop.org Delivered-To: intel-gfx@lists.freedesktop.org Received: from mga03.intel.com (mga03.intel.com [143.182.124.21]) by gabe.freedesktop.org (Postfix) with ESMTP id 2F4246EECD for ; Fri, 25 Apr 2014 07:58:45 -0700 (PDT) Received: from fmsmga001.fm.intel.com ([10.253.24.23]) by azsmga101.ch.intel.com with ESMTP; 25 Apr 2014 07:58:44 -0700 X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="4.97,927,1389772800"; d="scan'208";a="519760804" Received: from intel.iwi.intel.com ([172.28.253.39]) by fmsmga001.fm.intel.com with ESMTP; 25 Apr 2014 07:58:43 -0700 From: tim.gore@intel.com To: intel-gfx@lists.freedesktop.org Date: Fri, 25 Apr 2014 15:58:39 +0100 Message-Id: <1398437920-17394-3-git-send-email-tim.gore@intel.com> X-Mailer: git-send-email 1.9.2 In-Reply-To: <1398437920-17394-1-git-send-email-tim.gore@intel.com> References: <1398437920-17394-1-git-send-email-tim.gore@intel.com> Subject: [Intel-gfx] [PATCH 2/3] libdrm: fix more potential security issues X-BeenThere: intel-gfx@lists.freedesktop.org X-Mailman-Version: 2.1.15 Precedence: list List-Id: Intel graphics driver community testing & development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , MIME-Version: 1.0 Errors-To: intel-gfx-bounces@lists.freedesktop.org Sender: "Intel-gfx" X-Spam-Status: No, score=-4.8 required=5.0 tests=BAYES_00, RCVD_IN_DNSWL_MED, RP_MATCHES_RCVD, UNPARSEABLE_RELAY autolearn=unavailable version=3.3.1 X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on mail.kernel.org X-Virus-Scanned: ClamAV using ClamSMTP From: Tim Gore A static analysis of libdrm source code has identified several potential bugs. This commit addresses the critical issues in xf86drmHash.c, which are all potential null pointer dereferences. NOTE: I have kept to the indenting style already used in this file, which is a mixture of spaces and tabs. Signed-off-by: Tim Gore --- xf86drmHash.c | 12 ++++++++++-- 1 file changed, 10 insertions(+), 2 deletions(-) diff --git a/xf86drmHash.c b/xf86drmHash.c index 82cbc2a..7e6ba44 100644 --- a/xf86drmHash.c +++ b/xf86drmHash.c @@ -91,6 +91,7 @@ #define HASH_RANDOM_INIT(seed) srandom(seed) #define HASH_RANDOM random() #define HASH_RANDOM_DESTROY +#define HASH_RANDOM_OK (1) #else #define HASH_ALLOC drmMalloc #define HASH_FREE drmFree @@ -98,6 +99,7 @@ #define HASH_RANDOM_INIT(seed) state = drmRandomCreate(seed) #define HASH_RANDOM drmRandom(state) #define HASH_RANDOM_DESTROY drmRandomDestroy(state) +#define HASH_RANDOM_OK (state != NULL) #endif @@ -137,8 +139,14 @@ static unsigned long HashHash(unsigned long key) if (!init) { HASH_RANDOM_DECL; HASH_RANDOM_INIT(37); - for (i = 0; i < 256; i++) scatter[i] = HASH_RANDOM; - HASH_RANDOM_DESTROY; + if (HASH_RANDOM_OK) { + for (i = 0; i < 256; i++) scatter[i] = HASH_RANDOM; + HASH_RANDOM_DESTROY; + } else { + /* if we failed to allocate our random number state, fall back on random() */ + srandom(37); + for (i = 0; i < 256; i++) scatter[i] = random(); + } ++init; }