tty: rocket: Fix possible buffer overwrite on register_PCI
authorAnton Vasilyev <vasilyev@ispras.ru>
Fri, 27 Jul 2018 13:39:31 +0000 (16:39 +0300)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Thu, 2 Aug 2018 08:11:32 +0000 (10:11 +0200)
If number of isa and pci boards exceed NUM_BOARDS on the path
rp_init()->init_PCI()->register_PCI() then buffer overwrite occurs
in register_PCI() on assign rcktpt_io_addr[i].

The patch adds check on upper bound for index of registered
board in register_PCI.

Found by Linux Driver Verification project (linuxtesting.org).

Signed-off-by: Anton Vasilyev <vasilyev@ispras.ru>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
drivers/tty/rocket.c

index bdd17d2aaafd957d81b382eb16e8fa1f814bb004..b121d8f8f3d7d1a9d1dfc4341d61d51a5253a3f1 100644 (file)
@@ -1881,7 +1881,7 @@ static __init int register_PCI(int i, struct pci_dev *dev)
        ByteIO_t UPCIRingInd = 0;
 
        if (!dev || !pci_match_id(rocket_pci_ids, dev) ||
-           pci_enable_device(dev))
+           pci_enable_device(dev) || i >= NUM_BOARDS)
                return 0;
 
        rcktpt_io_addr[i] = pci_resource_start(dev, 0);