1. Jul 20, 2020
  2. Jul 18, 2020
  3. Jul 17, 2020
  4. Jul 16, 2020
    • George Kennedy's avatar
      ax88172a: fix ax88172a_unbind() failures · c28d9a28
      George Kennedy authored
      If ax88172a_unbind() fails, make sure that the return code is
      less than zero so that cleanup is done properly and avoid UAF.
      
      Fixes: a9a51bd7
      
       ("ax88172a: fix information leak on short answers")
      Signed-off-by: default avatarGeorge Kennedy <george.kennedy@oracle.com>
      Reported-by: default avatar <syzbot+4cd84f527bf4a10fc9c1@syzkaller.appspotmail.com>
      Signed-off-by: default avatarJakub Kicinski <kuba@kernel.org>
      c28d9a28
    • Stefano Garzarella's avatar
      vsock/virtio: annotate 'the_virtio_vsock' RCU pointer · f961134a
      Stefano Garzarella authored
      Commit 0deab087 ("vsock/virtio: use RCU to avoid use-after-free
      on the_virtio_vsock") starts to use RCU to protect 'the_virtio_vsock'
      pointer, but we forgot to annotate it.
      
      This patch adds the annotation to fix the following sparse errors:
      
          net/vmw_vsock/virtio_transport.c:73:17: error: incompatible types in comparison expression (different address spaces):
          net/vmw_vsock/virtio_transport.c:73:17:    struct virtio_vsock [noderef] __rcu *
          net/vmw_vsock/virtio_transport.c:73:17:    struct virtio_vsock *
          net/vmw_vsock/virtio_transport.c:171:17: error: incompatible types in comparison expression (different address spaces):
          net/vmw_vsock/virtio_transport.c:171:17:    struct virtio_vsock [noderef] __rcu *
          net/vmw_vsock/virtio_transport.c:171:17:    struct virtio_vsock *
          net/vmw_vsock/virtio_transport.c:207:17: error: incompatible types in comparison expression (different address spaces):
          net/vmw_vsock/virtio_transport.c:207:17:    struct virtio_vsock [noderef] __rcu *
          net/vmw_vsock/virtio_transport.c:207:17:    struct virtio_vsock *
          net/vmw_vsock/virtio_transport.c:561:13: error: incompatible types in comparison expression (different address spaces):
          net/vmw_vsock/virtio_transport.c:561:13:    struct virtio_vsock [noderef] __rcu *
          net/vmw_vsock/virtio_transport.c:561:13:    struct virtio_vsock *
          net/vmw_vsock/virtio_transport.c:612:9: error: incompatible types in comparison expression (different address spaces):
          net/vmw_vsock/virtio_transport.c:612:9:    struct virtio_vsock [noderef] __rcu *
          net/vmw_vsock/virtio_transport.c:612:9:    struct virtio_vsock *
          net/vmw_vsock/virtio_transport.c:631:9: error: incompatible types in comparison expression (different address spaces):
          net/vmw_vsock/virtio_transport.c:631:9:    struct virtio_vsock [noderef] __rcu *
          net/vmw_vsock/virtio_transport.c:631:9:    struct virtio_vsock *
      
      Fixes: 0deab087
      
       ("vsock/virtio: use RCU to avoid use-after-free on the_virtio_vsock")
      Reported-by: default avatarMichael S. Tsirkin <mst@redhat.com>
      Signed-off-by: default avatarStefano Garzarella <sgarzare@redhat.com>
      Reviewed-by: default avatarStefan Hajnoczi <stefanha@redhat.com>
      Acked-by: default avatarMichael S. Tsirkin <mst@redhat.com>
      Signed-off-by: default avatarJakub Kicinski <kuba@kernel.org>
      f961134a
    • Ioana Ciornei's avatar
      dpaa2-eth: check fsl_mc_get_endpoint for IS_ERR_OR_NULL() · 841eb401
      Ioana Ciornei authored
      The fsl_mc_get_endpoint() function can return an error or directly a
      NULL pointer in case the peer device is not under the root DPRC
      container. Treat this case also, otherwise it would lead to a NULL
      pointer when trying to access the peer fsl_mc_device.
      
      Fixes: 71947923
      
       ("dpaa2-eth: add MAC/PHY support through phylink")
      Signed-off-by: default avatarIoana Ciornei <ioana.ciornei@nxp.com>
      Signed-off-by: default avatarJakub Kicinski <kuba@kernel.org>
      841eb401
  5. Jul 15, 2020
  6. Jul 14, 2020
    • David S. Miller's avatar
      Merge tag 'wireless-drivers-2020-07-13' of... · d113c0f2
      David S. Miller authored
      Merge tag 'wireless-drivers-2020-07-13' of git://git.kernel.org/pub/scm/linux/kernel/git/kvalo/wireless-drivers
      
      
      
      Kalle Valo says:
      
      ====================
      wireless-drivers fixes for v5.8
      
      First set of fixes for v5.8. Various important fixes for iwlwifi and
      mt76.
      
      iwlwifi
      
      * fix sleeping under RCU
      
      * fix a kernel crash when using compressed firmware images
      
      mt76
      
      * tx queueing fixes for mt7615/22/63
      
      * locking fix
      
      * fix a crash during watchdog reset
      
      * fix memory leaks
      ====================
      
      Signed-off-by: default avatarDavid S. Miller <davem@davemloft.net>
      d113c0f2
    • Wei Yongjun's avatar
      ip6_gre: fix null-ptr-deref in ip6gre_init_net() · 46ef5b89
      Wei Yongjun authored
      KASAN report null-ptr-deref error when register_netdev() failed:
      
      KASAN: null-ptr-deref in range [0x00000000000003c0-0x00000000000003c7]
      CPU: 2 PID: 422 Comm: ip Not tainted 5.8.0-rc4+ #12
      Call Trace:
       ip6gre_init_net+0x4ab/0x580
       ? ip6gre_tunnel_uninit+0x3f0/0x3f0
       ops_init+0xa8/0x3c0
       setup_net+0x2de/0x7e0
       ? rcu_read_lock_bh_held+0xb0/0xb0
       ? ops_init+0x3c0/0x3c0
       ? kasan_unpoison_shadow+0x33/0x40
       ? __kasan_kmalloc.constprop.0+0xc2/0xd0
       copy_net_ns+0x27d/0x530
       create_new_namespaces+0x382/0xa30
       unshare_nsproxy_namespaces+0xa1/0x1d0
       ksys_unshare+0x39c/0x780
       ? walk_process_tree+0x2a0/0x2a0
       ? trace_hardirqs_on+0x4a/0x1b0
       ? _raw_spin_unlock_irq+0x1f/0x30
       ? syscall_trace_enter+0x1a7/0x330
       ? do_syscall_64+0x1c/0xa0
       __x64_sys_unshare+0x2d/0x40
       do_syscall_64+0x56/0xa0
       entry_SYSCALL_64_after_hwframe+0x44/0xa9
      
      ip6gre_tunnel_uninit() has set 'ign->fb_tunnel_dev' to NULL, later
      access to ign->fb_tunnel_dev cause null-ptr-deref. Fix it by saving
      'ign->fb_tunnel_dev' to local variable ndev.
      
      Fixes: dafabb65
      
       ("ip6_gre: fix use-after-free in ip6gre_tunnel_lookup()")
      Reported-by: default avatarHulk Robot <hulkci@huawei.com>
      Signed-off-by: default avatarWei Yongjun <weiyongjun1@huawei.com>
      Reviewed-by: default avatarEric Dumazet <edumazet@google.com>
      Signed-off-by: default avatarDavid S. Miller <davem@davemloft.net>
      46ef5b89
    • Geert Uytterhoeven's avatar
      usb: hso: Fix debug compile warning on sparc32 · e0484010
      Geert Uytterhoeven authored
      
      
      On sparc32, tcflag_t is "unsigned long", unlike on all other
      architectures, where it is "unsigned int":
      
          drivers/net/usb/hso.c: In function ‘hso_serial_set_termios’:
          include/linux/kern_levels.h:5:18: warning: format ‘%d’ expects argument of type ‘unsigned int’, but argument 4 has type ‘tcflag_t {aka long unsigned int}’ [-Wformat=]
          drivers/net/usb/hso.c:1393:3: note: in expansion of macro ‘hso_dbg’
             hso_dbg(0x16, "Termios called with: cflags new[%d] - old[%d]\n",
             ^~~~~~~
          include/linux/kern_levels.h:5:18: warning: format ‘%d’ expects argument of type ‘unsigned int’, but argument 5 has type ‘tcflag_t {aka long unsigned int}’ [-Wformat=]
          drivers/net/usb/hso.c:1393:3: note: in expansion of macro ‘hso_dbg’
             hso_dbg(0x16, "Termios called with: cflags new[%d] - old[%d]\n",
             ^~~~~~~
      
      As "unsigned long" is 32-bit on sparc32, fix this by casting all tcflag_t
      parameters to "unsigned int".
      While at it, use "%u" to format unsigned numbers.
      
      Signed-off-by: default avatarGeert Uytterhoeven <geert@linux-m68k.org>
      Signed-off-by: default avatarDavid S. Miller <davem@davemloft.net>
      e0484010
  7. Jul 13, 2020
  8. Jul 11, 2020