Skip to content

Commit 9225c0b

Browse files
Al Virogregkh
authored andcommitted
staging: lustre: echo_copy.._lsm() dereferences userland pointers directly
missing get_user() Signed-off-by: Al Viro <viro@zeniv.linux.org.uk> Cc: stable <stable@vger.kernel.org> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
1 parent cc4c60c commit 9225c0b

File tree

1 file changed

+11
-9
lines changed

1 file changed

+11
-9
lines changed

drivers/staging/lustre/lustre/obdecho/echo_client.c

Lines changed: 11 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -1270,6 +1270,7 @@ static int
12701270
echo_copyout_lsm(struct lov_stripe_md *lsm, void *_ulsm, int ulsm_nob)
12711271
{
12721272
struct lov_stripe_md *ulsm = _ulsm;
1273+
struct lov_oinfo **p;
12731274
int nob, i;
12741275

12751276
nob = offsetof(struct lov_stripe_md, lsm_oinfo[lsm->lsm_stripe_count]);
@@ -1279,19 +1280,21 @@ echo_copyout_lsm(struct lov_stripe_md *lsm, void *_ulsm, int ulsm_nob)
12791280
if (copy_to_user(ulsm, lsm, sizeof(*ulsm)))
12801281
return -EFAULT;
12811282

1282-
for (i = 0; i < lsm->lsm_stripe_count; i++) {
1283-
if (copy_to_user(ulsm->lsm_oinfo[i], lsm->lsm_oinfo[i],
1284-
sizeof(lsm->lsm_oinfo[0])))
1283+
for (i = 0, p = lsm->lsm_oinfo; i < lsm->lsm_stripe_count; i++, p++) {
1284+
struct lov_oinfo __user *up;
1285+
if (get_user(up, ulsm->lsm_oinfo + i) ||
1286+
copy_to_user(up, *p, sizeof(struct lov_oinfo)))
12851287
return -EFAULT;
12861288
}
12871289
return 0;
12881290
}
12891291

12901292
static int
12911293
echo_copyin_lsm(struct echo_device *ed, struct lov_stripe_md *lsm,
1292-
void *ulsm, int ulsm_nob)
1294+
struct lov_stripe_md __user *ulsm, int ulsm_nob)
12931295
{
12941296
struct echo_client_obd *ec = ed->ed_ec;
1297+
struct lov_oinfo **p;
12951298
int i;
12961299

12971300
if (ulsm_nob < sizeof(*lsm))
@@ -1306,11 +1309,10 @@ echo_copyin_lsm(struct echo_device *ed, struct lov_stripe_md *lsm,
13061309
((__u64)lsm->lsm_stripe_size * lsm->lsm_stripe_count > ~0UL))
13071310
return -EINVAL;
13081311

1309-
for (i = 0; i < lsm->lsm_stripe_count; i++) {
1310-
if (copy_from_user(lsm->lsm_oinfo[i],
1311-
((struct lov_stripe_md *)ulsm)-> \
1312-
lsm_oinfo[i],
1313-
sizeof(lsm->lsm_oinfo[0])))
1312+
for (i = 0, p = lsm->lsm_oinfo; i < lsm->lsm_stripe_count; i++, p++) {
1313+
struct lov_oinfo __user *up;
1314+
if (get_user(up, ulsm->lsm_oinfo + i) ||
1315+
copy_from_user(*p, up, sizeof(struct lov_oinfo)))
13141316
return -EFAULT;
13151317
}
13161318
return 0;

0 commit comments

Comments
 (0)