summaryrefslogtreecommitdiff
path: root/tools/perf/scripts/python/flamegraph.py
diff options
context:
space:
mode:
authorJann Horn <jannh@google.com>2025-02-12 21:15:15 +0300
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>2025-02-14 11:21:56 +0300
commite563b01208f4d1f609bcab13333b6c0e24ce6a01 (patch)
tree6f4b453316081ee4221fb3b06d8f7e4875f408aa /tools/perf/scripts/python/flamegraph.py
parentc81d9fcd5b9402166048f377d4e5e0ee6f9ef26d (diff)
downloadlinux-e563b01208f4d1f609bcab13333b6c0e24ce6a01.tar.xz
usb: cdc-acm: Check control transfer buffer size before access
If the first fragment is shorter than struct usb_cdc_notification, we can't calculate an expected_size. Log an error and discard the notification instead of reading lengths from memory outside the received data, which can lead to memory corruption when the expected_size decreases between fragments, causing `expected_size - acm->nb_index` to wrap. This issue has been present since the beginning of git history; however, it only leads to memory corruption since commit ea2583529cd1 ("cdc-acm: reassemble fragmented notifications"). A mitigating factor is that acm_ctrl_irq() can only execute after userspace has opened /dev/ttyACM*; but if ModemManager is running, ModemManager will do that automatically depending on the USB device's vendor/product IDs and its other interfaces. Cc: stable <stable@kernel.org> Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") Signed-off-by: Jann Horn <jannh@google.com> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Diffstat (limited to 'tools/perf/scripts/python/flamegraph.py')
0 files changed, 0 insertions, 0 deletions