From patchwork Fri Aug 5 19:44:10 2016 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Dave Carroll X-Patchwork-Id: 9265697 Return-Path: Received: from mail.wl.linuxfoundation.org (pdx-wl-mail.web.codeaurora.org [172.30.200.125]) by pdx-korg-patchwork.web.codeaurora.org (Postfix) with ESMTP id E001F60760 for ; Fri, 5 Aug 2016 19:45:06 +0000 (UTC) Received: from mail.wl.linuxfoundation.org (localhost [127.0.0.1]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id C2C7127F0B for ; Fri, 5 Aug 2016 19:45:06 +0000 (UTC) Received: by mail.wl.linuxfoundation.org (Postfix, from userid 486) id B426C2842E; Fri, 5 Aug 2016 19:45:06 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on pdx-wl-mail.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-6.8 required=2.0 tests=BAYES_00,DKIM_SIGNED, RCVD_IN_DNSWL_HI,T_DKIM_INVALID autolearn=ham version=3.3.1 Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id D437A27F0B for ; Fri, 5 Aug 2016 19:45:05 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S2992827AbcHETo4 (ORCPT ); Fri, 5 Aug 2016 15:44:56 -0400 Received: from mail-bn3nam01on0060.outbound.protection.outlook.com ([104.47.33.60]:44632 "EHLO NAM01-BN3-obe.outbound.protection.outlook.com" rhost-flags-OK-OK-OK-FAIL) by vger.kernel.org with ESMTP id S1949451AbcHETos (ORCPT ); Fri, 5 Aug 2016 15:44:48 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mscc365.onmicrosoft.com; s=selector1-microsemi-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=CyccKCRFRhck6Kg2kVs8PUJO97z3hocpOmJwdHQ2SGw=; b=chnkYos3nYQ6nzeZx8mGMQpl/2bvCHylP0mJ1YuKT/4BHplwYSCgtssLpDfyub+BENe7hQuc6t4gtJVoS5/zIUupwR0jGWIpr4XN3cYYq7uhXpCO1jnvlA6c/ADRCy/s/oHkFuD46dIiAwrXrF7WlIuxciE9NUV+jJN+v7IUNIw= Received: from BY2PR02CA0121.namprd02.prod.outlook.com (10.163.44.175) by SN1PR0201MB1518.namprd02.prod.outlook.com (10.163.129.17) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P384) id 15.1.549.15; Fri, 5 Aug 2016 19:44:44 +0000 Received: from BN1BFFO11FD042.protection.gbl (2a01:111:f400:7c10::1:182) by BY2PR02CA0121.outlook.office365.com (2a01:111:e400:5261::47) with Microsoft SMTP Server (version=TLS1_0, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA_P384) id 15.1.549.15 via Frontend Transport; Fri, 5 Aug 2016 19:44:44 +0000 Authentication-Results: spf=none (sender IP is 208.19.100.21) smtp.mailfrom=microsemi.com; vger.kernel.org; dkim=none (message not signed) header.d=none;vger.kernel.org; dmarc=none action=none header.from=microsemi.com; Received-SPF: None (protection.outlook.com: microsemi.com does not designate permitted sender hosts) Received: from avsrvexchhts1.microsemi.net (208.19.100.21) by BN1BFFO11FD042.mail.protection.outlook.com (10.58.144.105) with Microsoft SMTP Server (version=TLS1_0, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA_P384) id 15.1.557.8 via Frontend Transport; Fri, 5 Aug 2016 19:44:44 +0000 Received: from localhost.localdomain (10.225.65.2) by avsrvexchhts1.microsemi.net (10.100.34.105) with Microsoft SMTP Server id 14.3.301.0; Fri, 5 Aug 2016 12:44:41 -0700 From: Dave Carroll To: James Bottomley , "Martin K . Petersen" CC: , , , Dave Carroll , Linux-SCSI , Johannes Thumshurn , Subject: [PATCH V2] aacraid: Check size values after double-fetch from user Date: Fri, 5 Aug 2016 13:44:10 -0600 Message-ID: <20160805194410.7198-1-david.carroll@microsemi.com> X-Mailer: git-send-email 2.8.4 MIME-Version: 1.0 X-EOPAttributedMessage: 0 X-Forefront-Antispam-Report: CIP:208.19.100.21; IPV:NLI; CTRY:US; EFV:NLI; SFV:NSPM; SFS:(10009020)(6009001)(7916002)(2980300002)(428002)(189002)(199003)(49486002)(87936001)(356003)(77096005)(50466002)(15975445007)(50226002)(92566002)(48376002)(101416001)(2906002)(50986999)(97736004)(5001770100001)(106466001)(229853001)(4326007)(47776003)(189998001)(5003940100001)(7846002)(33646002)(86362001)(68736007)(19580405001)(104016004)(19580395003)(69596002)(586003)(8676002)(11100500001)(305945005)(36756003)(81166006)(8936002)(81156014)(105586002)(1076002); DIR:OUT; SFP:1101; SCL:1; SRVR:SN1PR0201MB1518; H:avsrvexchhts1.microsemi.net; FPR:; SPF:None; PTR:InfoDomainNonexistent; MX:1; A:1; LANG:en; X-Microsoft-Exchange-Diagnostics: 1; BN1BFFO11FD042; 1:tNh884S21qDit4jaQn1iFaxWvBk6MX37NrubxwM3t8t/cTmmWdi2fIQGW1/Qrte/0jl7xaVXQ4DXEiQtzCRy/ZfmXfWuNYQIW3i8zq/sQmPQITmxwza/rO7D25fqskbg2b9aCP7NIYz7IjTRIFLblI4J/vbLedZbLUPXkIBy9LdeOUSDb2lcBVuwZI1jtkWhefBMrf0KmtbuGZrkqOwgh7nbXFW7jXe46z+A4vHu0f3sTtUNOfXHrGGrdeUKYSM/6q3XqxtZg5/cfNB3wB+AuXz3F7BkqabfOiB+X+Q7ZHslsaRinXsi9JpA6UbDwhnXW+GrQW6z3NPsgDmBgx5s+VVuC4Kn6kS2Lt6S2u2kKBDrY5bD7iEqJSHktJE2twJldxYhOLGrzEibsgau6OsIXjn8umgelSVqqLX8Hg+KgN0Z8SQrUDMTO3ljVg1/mHQP1osjuHIL6vF5T/TfM21RuRlw6m4wY/z0maiBJlmXTc8pjOINdPxBeEycsGNEuD2aNPXhqjY86sXm/l/reXznyvPXkfA7fHfMgSLAqboya1g= X-MS-Office365-Filtering-Correlation-Id: 4bf372f6-037b-4fe6-bb04-08d3bd68f33e X-Microsoft-Exchange-Diagnostics: 1; SN1PR0201MB1518; 2:A2N66lYJJ484Wr9wMusQbueL/a/YJlJaF+uwMVnDw7uOTBikNmCsbUNphN1BtLdfInlnvyUqBnQF9jqhob8scqOzBF9p/DX+lf+3vEXyJZ4lPBmhTjQ+D8WbnZBabgro2zMwmpb3aX04WGKpxZatxoX22cWWCOMJjzBDrrfn2LJeK7l6h6N44vU0CDbacp9l; 3:ZrF0ucj+VMmQlvqJhGtCM/1j9NfZdURw4FeJbYLWnNfzP3JmtVwi4i0wV1mhZRYs+hylMLcbFf6Q1kceipJQdGFAfHtTyEO+8JMbcCHLmu11Kntj1c83t9IoQOIJE0tJhjbDGXbO0x1KENYHNEqvmaOdP6PJnva5JuLEtjZD8NGlsZpg/Ff9Wh/V8cSOg7c9s0sY+P1PpcD3Ol3it4ZCZs8oqs4cqGDZr6GBbbVrU+0= X-Microsoft-Antispam: UriScan:;BCL:0;PCL:0;RULEID:;SRVR:SN1PR0201MB1518; X-Microsoft-Exchange-Diagnostics: 1; SN1PR0201MB1518; 25:Qz4Wn0QCZai8pI7CpFrLTI5vSWz0RatvC+QuN7erRsAHZoTEB0uDKGY++T9+0+FsD58WhqiDO5bBCKu4B5gUSkQbjxJ2moJ6Vb8oavf//1ZAXF/SV/2g862AETq5UT9lPnT2JcE3YujTG2MJqPuNpxFQyZwPyeRzwLrZAFKQXxUeD8G+dmkmyr95f5zn6HaIeTa1gUJDoshVxr/91t1CMhEoMp5o71jADKIIhv2lvQE5EyYVGTs2IrXwpVC6ij4+u73PyNouR7R956aDR4yZk4bIxw9JrqVwzXKsFKr1nSUpo08t9Hm7BIApS/dNaAmBy0KYNBCpIDLWAeQO7n2Ep3P2tzbAosmfjvnb6d9L3nIoVv41xkjeF25It7NXFeej5bszJqp+efn5TbKrtA+5PHVb+M0bKqoY2JV1X+LzuRmxGbtb5VWrIAwkKF7Q2fbj4nnLnf+Qff1Cp2/mZUOzEpaK0YIIi5rTROO2HVvQDUWizqxy/stAhJpadUT1Esj2NW5n0uXh1xxqqh4Hd7mA8MuPwFqDEw3nQ1lMJALj8frAPJB/6gTFRBIi3OLncLpgKzptJ+TYFklNSvZYk4njIzx8uN+8xEnLW4KfQHtKk7Pj7x0AaV8g57t4mYYaw0koFIHLshZYN5UMGMEpKvHxI5a5L1/JdIyUn4tCRrJG9tSXpcj+q9Njq6VUQzi/nexQC8X02kaYHi4OOFzLSCuiyny9vl6g/1nBGe9MZM2vMgaYApfzlFc4oJE0fc/2X7OLWJPIBsh/5X1T0KXFprbmbiqxJuh/A1jAaHiengAEZBQMuHNGikU1/299Oi+LKP7a9VkC/eYiYH4gS4dlaGoZwqKRwRqGVj+19vaALYpzRxc= X-Microsoft-Exchange-Diagnostics: 1; SN1PR0201MB1518; 31:QvrIW1iXe+UjcLAmjzMAkEjLTdTyUdU/bV/u/wWotV6s5ssy7I3FQkBGDhXHGh8YPuWA0gXVdA9/wBls9dUhKunhKfbUWAFqsxOnVpQP1UsJyiZBQl/jut3G3GMfJCwN7VOOI/pcwyeNx29CW/aoFX2YMJmcMvwN7blnwnCSByiQEH3yOjtDbwd+Rud+FLPnIawhFHEkNyJoLcF0t/rLcyPsDK7lfbqJg/jXJKjHrQk=; 20:v9J+GSwZUDzwx9AnnscAcsOElWyRFlvAuV/SzXYJlshr4rvnVqlH4hwctRXzrLlrlTujSzSJT7a0/93z4aHRv9NEw5Fo0l/RmYgWQU7qpc4bycpGXhp58G1YSfjKplxZVaBZRLDl8o9nMsAFe9871oMN9IfxnFxyG6F/rXoekP7PeapLQ6aGBhYV/Fh33zcetZUnjn4YlnBROLqNVSt6/jJQf6yHP+awu/VG8NU+byvoe950uN4TwU9vKLGj1i9jxEaS9kj+B1O2M20C++Ups+goNRA9hZIv2DZUDRoIvsMs2YkGsZ9nf83TXK7wYukgp/lLV2U4orKzJFpS2LKJz/gNjCl5QqGLJ63WhUMiNpYts4BrDK+3GNUumU1osNqExBSs+oh96LKUTjz9cE4wxn+GrGWqPyYUAnm5A6L7/lAY64H5UB9zO49T2yN1tiglUMm7BGEkiysbLW3M9RgZNNqYQ/txZloLeMaJ6bYfbZWFhnw8hDUl63gB3n1rWC9Z X-Microsoft-Antispam-PRVS: X-Exchange-Antispam-Report-Test: UriScan:(9452136761055)(72170198267865); X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(601004)(2401047)(13023025)(13024025)(13015025)(13018025)(13017025)(8121501046)(5005006)(10201501046)(3002001); SRVR:SN1PR0201MB1518; BCL:0; PCL:0; RULEID:; SRVR:SN1PR0201MB1518; X-Microsoft-Exchange-Diagnostics: 1; SN1PR0201MB1518; 4:KOLZ2AQ6eXIDC6Fx4M4Tb4wL0xAHOlDlLvuPhO5MbyIAHOiRwnRaphwlgN3Vx1R0A3fd9yVPjV+ltzNqgYVavaFJef/0tPnbjufRL0eWCUBAuUt8elriFwrSWfSceYTycyr2XyOzo4N1hP5hKTJ5Ua8ZcI0nl7fyCSrQWxyHb8u7JsKGROOk+fCqvjE1PQI/NNZHCLrckwIRTR9dHZ7cxC0vGqd1tRS4omf03O+I5McZgInNq1WsYEn1tCU0fLpAIqj1NkJ+3gPEho8DzT9XH0cJIwYuOxGvC4qcQU8rHXaQAixHGmvd9Vw83l09E2LGz8+dLotD9smatkSbpZSIVOGs1O+N3WnUNsb/DYU0+gsT5nYTtJDVGyBvx5wa7ymgV7vqRUJLgnb3fFCpF37LYOzzc7viEv/HNfg2ftxskcNJqFyGMAaOOo3LkHtTRI4VeWWFldrX5VoODkfm2UBcD+sbbGSbUhg3bV5Mc5tx2WOUsG693M6rGq6QJq/KQ2XY596VHjbuBol5TVNQAoxrl8ukCdB0b6rcSZxHSvBulVw= X-Forefront-PRVS: 0025434D2D X-Microsoft-Exchange-Diagnostics: =?us-ascii?Q?1; SN1PR0201MB1518; 23:FF9kTqUHz796uhouG2kjtK61d68LwyU2JzfAsNw?= =?us-ascii?Q?wuTwNe7SJeTXVPKyPzS/8ZmIz8v0afZGXTz0yWb6rfxNuYtnSoDC3nawEt6A?= =?us-ascii?Q?ZuK76n6od31srZl+PNe4EqS4aF6tt5ek3hG+DxCptsk9y34xnYCz4CT/ei3x?= =?us-ascii?Q?k3g3cdClWHGpEaPhiazpra41wO33tJTcQZIJ8KehPOY0YHYn0E/nqXaMLqwC?= =?us-ascii?Q?hS+WrK7+kl/8IjXe8Y3gaKaSwJVb5KfrVKTi2TgC1RjkvuOcSxGofwzu3xOK?= =?us-ascii?Q?VxOvBmBjwYumVi2oxsbQKv/k6TA2QDRflxd+MVNiJSit7Eq1/bjPC5PPyTDG?= =?us-ascii?Q?t/MkwjnuzwCj7GnOULiBoOcwLg6vpRkxRmgIrm+253QXqsC2bQo+VBLrWWCE?= =?us-ascii?Q?hYx2vgokoK/xQTaOPPxuUEcBZ6WeNxVaYIZGol7mexDMUNZ5fw/ywXHkiRoP?= =?us-ascii?Q?IGrSYImsdoSasGcuk/462uSgl0CTTOqiVBDoBXCKgAuWGhuvfmMoDKvBRhOR?= =?us-ascii?Q?gKQN5EMu/dOJ2PfEjoWwfuVoBdsVJdbGMWRJOm3zO7yhwMlQJl95rLJMGwpL?= =?us-ascii?Q?yG4cRJfgsJPb3GqO2TXASg6kyNj5KX+omIGLif8W8p7eNKm8jdXHXIAZOjdT?= =?us-ascii?Q?ErkE3QJ9NsuMHRdTNZXQhCtMyH1N1VLJqhrYDIN0/DpA4hAjO3FqrjOuPjh3?= =?us-ascii?Q?O5euP8Z6n9SDSrB/A9V0Hr0h0tdMV84wfd/tLU8c7HLTHWdTf9c7pn9HOBxY?= =?us-ascii?Q?RIm17iT8CT0putJpC9unhZbl64QhGUtsqHV+Jlv8/8o9dUbdfcpd5jP3++jp?= =?us-ascii?Q?IBIUDrHIWIdRuYPUSE4Z3K29rcnxOgNVYg3rNSAhEL60zU4ASkZmhLkoxQVQ?= =?us-ascii?Q?4iMeBd8VTpbjl+cdZG30n/hqaYFIcD/gw4AogrXGCo50BmL9txILajlbb688?= =?us-ascii?Q?g1n3HUGUmJhA5nf2vOc7GLeML33a/CSfP0UyDnY8YjJEyrBNXDmIAdonfxne?= =?us-ascii?Q?VvPaOXUa6BY/jakBBVsKYDM7Uf1jrbETrC52O+wD7X4HIPZbBkQWafMxU/6N?= =?us-ascii?Q?gAfQNnT27VF1UHdBk2xPdut0H8Yye?= X-Microsoft-Exchange-Diagnostics: 1; SN1PR0201MB1518; 6:lX7lxgo6QICo+j+hP6ozGUQwmWGdcnjoNUgFm5dm9DWsC6gZ88IgmOEVhlJdRuKAa1Hmilp5xn4WWPR4OTmJOOhBqrCo2Mgdmd0LzL5T6ZE1YnnJJ6+s26vnKL2Hheg5WcGlRlwC8lFNOP5G9X/SUfP0EAhQYCJ01fO17Bd89/hsOMaTVaIfoJEtAAtrQfxwS26d7XzNxHk+t5rGpiWdql3yA1n5fhiBq4Vm7FJFxPZ2z/YmBmFhp+eCOrr8M7kOxv/h40ggWXojwedWR4/Anq3aw2Qx7eMnl+ola3E9+m0=; 5:LMTA1k/K4jnZon4nK8KPrauQ8AsiTwIVMsssPq4WBD7nTf0rPa52r4jASwWL4mqtuDS3qD1qLJvXeH00jytEuBmFbAMoaE174ZLxBeAq/0kSiyKGvX8bhjI1uD3fpX6GOzDTieCtXig10hvfZ/EAYA==; 24:JxaSKA+6oPIOTetBwWuV/unNVO048k1CvI/R5cMuvQisb3KkrWWZdAVjnBv2gYZ2fx3lN3rzgM3QDh2+m60JDjA8XC/BsoFkVpIEHjwPwr4=; 7:rejUKmF5Br18YEiS4XBvpAM/Em8/WKPcfjQxPJHgcKVPxxykdXECkATQ9WwC6Qoksb3BN3h85//FreaprZT1cX+VqWRmzS9MMSOWrlp4QwQHvTi3X+Fzcf90aWbzHGHa9i6A1mcA8BqxwPn1zx0uUIaZsdWkacu+KDmnjKl/zY7Wp86O5gp5QpyytGq/UfxIGA7sh19v2malWZivbWoeJQckOi3qeosiULDgYCBBFguRnb8sDP4mOcfiB406FaNN SpamDiagnosticOutput: 1:99 SpamDiagnosticMetadata: NSPM X-OriginatorOrg: microsemi.com X-MS-Exchange-CrossTenant-OriginalArrivalTime: 05 Aug 2016 19:44:44.1318 (UTC) X-MS-Exchange-CrossTenant-Id: f267a5c8-86d8-4cc9-af71-1fd2c67c8fad X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=f267a5c8-86d8-4cc9-af71-1fd2c67c8fad; Ip=[208.19.100.21]; Helo=[avsrvexchhts1.microsemi.net] X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem X-MS-Exchange-Transport-CrossTenantHeadersStamped: SN1PR0201MB1518 Sender: linux-scsi-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-scsi@vger.kernel.org X-Virus-Scanned: ClamAV using ClamSMTP In aacraid's ioctl_send_fib() we do two fetches from userspace, one the get the fib header's size and one for the fib itself. Later we use the size field from the second fetch to further process the fib. If for some reason the size from the second fetch is different than from the first fix, we may encounter an out-of- bounds access in aac_fib_send(). We also check the sender size to insure it is not out of bounds. This was reported in https://bugzilla.kernel.org/show_bug.cgi?id=116751 and was assigned CVE- 2016-6480. Reported-by: Pengfei Wang Fixes: 7c00ffa31 '[SCSI] 2.6 aacraid: Variable FIB size (updated patch)' Cc: stable@vger.kernel.org Signed-off-by: Dave Carroll Reviewed-by: Johannes Thumshirn --- drivers/scsi/aacraid/commctrl.c | 11 +++++++++-- 1 file changed, 9 insertions(+), 2 deletions(-) diff --git a/drivers/scsi/aacraid/commctrl.c b/drivers/scsi/aacraid/commctrl.c index b381b37..eadca7b 100644 --- a/drivers/scsi/aacraid/commctrl.c +++ b/drivers/scsi/aacraid/commctrl.c @@ -63,7 +63,7 @@ static int ioctl_send_fib(struct aac_dev * dev, void __user *arg) struct fib *fibptr; struct hw_fib * hw_fib = (struct hw_fib *)0; dma_addr_t hw_fib_pa = (dma_addr_t)0LL; - unsigned size; + unsigned int size, osize; int retval; if (dev->in_reset) { @@ -87,7 +87,8 @@ static int ioctl_send_fib(struct aac_dev * dev, void __user *arg) * will not overrun the buffer when we copy the memory. Return * an error if we would. */ - size = le16_to_cpu(kfib->header.Size) + sizeof(struct aac_fibhdr); + osize = size = le16_to_cpu(kfib->header.Size) + + sizeof(struct aac_fibhdr); if (size < le16_to_cpu(kfib->header.SenderSize)) size = le16_to_cpu(kfib->header.SenderSize); if (size > dev->max_fib_size) { @@ -117,6 +117,14 @@ static int ioctl_send_fib(struct aac_dev * dev, void __user *arg) retval = -EFAULT; goto cleanup; } + + /* Sanity check the second copy */ + if ((osize != le16_to_cpu(kfib->header.Size) + + sizeof(struct aac_fibhdr)) + || (size < le16_to_cpu(kfib->header.SenderSize))) { + retval = -EINVAL; + goto cleanup; + } if (kfib->header.Command == cpu_to_le16(TakeABreakPt)) { aac_adapter_interrupt(dev);