staging/bcm: two information leaks in ioctl
authorDan Carpenter <dan.carpenter@oracle.com>
Mon, 17 Feb 2014 19:56:06 +0000 (22:56 +0300)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Tue, 18 Feb 2014 19:18:09 +0000 (11:18 -0800)
There are a couple paths where we don't check how much data we copy back
to the user.

Cc: Dave Jones <davej@redhat.com>
Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
drivers/staging/bcm/Bcmchar.c

index fdebc3bba0b50f4c6e3b670d85fe162a50bb2245..6f1997dc44c8e92f5dea2677f946ff00d10c8959 100644 (file)
@@ -590,6 +590,8 @@ static int bcm_char_ioctl_gpio_multi_request(void __user *argp, struct bcm_mini_
 
        if (IoBuffer.InputLength > sizeof(gpio_multi_info))
                return -EINVAL;
+       if (IoBuffer.OutputLength > sizeof(gpio_multi_info))
+               IoBuffer.OutputLength = sizeof(gpio_multi_info);
 
        if (copy_from_user(&gpio_multi_info, IoBuffer.InputBuffer, IoBuffer.InputLength))
                return -EFAULT;
@@ -680,6 +682,8 @@ static int bcm_char_ioctl_gpio_mode_request(void __user *argp, struct bcm_mini_a
 
        if (IoBuffer.InputLength > sizeof(gpio_multi_mode))
                return -EINVAL;
+       if (IoBuffer.OutputLength > sizeof(gpio_multi_mode))
+               IoBuffer.OutputLength = sizeof(gpio_multi_mode);
 
        if (copy_from_user(&gpio_multi_mode, IoBuffer.InputBuffer, IoBuffer.InputLength))
                return -EFAULT;