From patchwork Wed Oct 3 06:29:39 2018 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Po-Hsu Lin X-Patchwork-Id: 978126 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@bilbo.ozlabs.org Authentication-Results: ozlabs.org; spf=none (mailfrom) smtp.mailfrom=lists.ubuntu.com (client-ip=91.189.94.19; helo=huckleberry.canonical.com; envelope-from=kernel-team-bounces@lists.ubuntu.com; receiver=) Authentication-Results: ozlabs.org; dmarc=fail (p=none dis=none) header.from=canonical.com Received: from huckleberry.canonical.com (huckleberry.canonical.com [91.189.94.19]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 42Q5mS32Kxz9sBh; Wed, 3 Oct 2018 16:32:40 +1000 (AEST) Received: from localhost ([127.0.0.1] helo=huckleberry.canonical.com) by huckleberry.canonical.com with esmtp (Exim 4.86_2) (envelope-from ) id 1g7ahz-0007TS-S1; Wed, 03 Oct 2018 06:32:31 +0000 Received: from youngberry.canonical.com ([91.189.89.112]) by huckleberry.canonical.com with esmtps (TLS1.0:DHE_RSA_AES_128_CBC_SHA1:128) (Exim 4.86_2) (envelope-from ) id 1g7ahx-0007TA-I2 for kernel-team@lists.ubuntu.com; Wed, 03 Oct 2018 06:32:29 +0000 Received: from mail-pg1-f199.google.com ([209.85.215.199]) by youngberry.canonical.com with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.76) (envelope-from ) id 1g7ahx-0005L8-6M for kernel-team@lists.ubuntu.com; Wed, 03 Oct 2018 06:32:29 +0000 Received: by mail-pg1-f199.google.com with SMTP id q143-v6so1579590pgq.12 for ; Tue, 02 Oct 2018 23:32:29 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:subject:date:message-id:in-reply-to :references; bh=ZaE1qORJqHWVBtMOb8X4teZYU8xJAL0IQSzJRo/o9tQ=; b=FHnz/teLjhdh6M3mSgqd1VUr/B9iZOGsiwFH36DH3+LVUDq6tZCcVWBC0izKBJ3Es3 hM9mFsXnegh2DRcvSB3QPm9Ps3+yrfGVhagc8Kv8cQiinVO2cUq3uu48GrpbJ0lU0qo/ 4IGrUzhNnGbhdv5S3GEaI6TpKVj9OI9ooLMDRSgrMBrg/KZ1Nz5RU+n8CVZOe/aCOLxt xSHgfrnYNBwuQndJjKE3Qgk1BZThXcQQhuXwTREgHI5u/i07onCtz19woaaY+MO97ENI CBkn2Y76Qjo6kYGCYEVSz5v1bl+XPr/i/m4XGiPB0Q9CP4Uv7Xp3VU1QryP1psj9qlbZ 2nfg== X-Gm-Message-State: ABuFfohsFHNQlQIK8c7ohRZ4vDUYpWlhlgGkkSOxoiymNH0nV8+NBF2x XB0iZ/81cIKDLA0HrLDQTck1S8MBcj874KQqGKLOOY1Rf5dKnCSDmlFngEs7x0cOUxEFpGjJz0h RRCY9Wk0Hfv7DfzAY6IYH+tla53LKJjuyPCKuCScE X-Received: by 2002:a17:902:b403:: with SMTP id x3-v6mr11688plr.237.1538548347587; Tue, 02 Oct 2018 23:32:27 -0700 (PDT) X-Google-Smtp-Source: ACcGV610PQBD1A0NSP5nBlB64xLmN5Nq/G6ZS6/CX5ODAQhIyVj9pG6ZBpNrIvx7jn4qCK7uVhRPlg== X-Received: by 2002:a17:902:b403:: with SMTP id x3-v6mr11678plr.237.1538548347399; Tue, 02 Oct 2018 23:32:27 -0700 (PDT) Received: from Leggiero.taipei.internal (61-220-137-37.HINET-IP.hinet.net. [61.220.137.37]) by smtp.gmail.com with ESMTPSA id j15-v6sm674151pfn.52.2018.10.02.23.32.25 for (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 02 Oct 2018 23:32:26 -0700 (PDT) From: Po-Hsu Lin To: kernel-team@lists.ubuntu.com Subject: [CVE-2018-16658][Trusty][Bionic][SRU][PATCH 1/1] cdrom: Fix info leak/OOB read in cdrom_ioctl_drive_status Date: Wed, 3 Oct 2018 14:29:39 +0800 Message-Id: <20181003062939.16699-2-po-hsu.lin@canonical.com> X-Mailer: git-send-email 2.17.1 In-Reply-To: <20181003062939.16699-1-po-hsu.lin@canonical.com> References: <20181003062939.16699-1-po-hsu.lin@canonical.com> X-BeenThere: kernel-team@lists.ubuntu.com X-Mailman-Version: 2.1.20 Precedence: list List-Id: Kernel team discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , MIME-Version: 1.0 Errors-To: kernel-team-bounces@lists.ubuntu.com Sender: "kernel-team" From: Scott Bauer CVE-2018-16658 Like d88b6d04: "cdrom: information leak in cdrom_ioctl_media_changed()" There is another cast from unsigned long to int which causes a bounds check to fail with specially crafted input. The value is then used as an index in the slot array in cdrom_slot_status(). Signed-off-by: Scott Bauer Signed-off-by: Scott Bauer Cc: stable@vger.kernel.org Signed-off-by: Jens Axboe (cherry picked from commit 8f3fafc9c2f0ece10832c25f7ffcb07c97a32ad4) Signed-off-by: Po-Hsu Lin Acked-by: Stefan Bader Acked-by: Kleber Sacilotto de Souza --- drivers/cdrom/cdrom.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/cdrom/cdrom.c b/drivers/cdrom/cdrom.c index cbee2e7..f0534a4 100644 --- a/drivers/cdrom/cdrom.c +++ b/drivers/cdrom/cdrom.c @@ -2542,7 +2542,7 @@ static int cdrom_ioctl_drive_status(struct cdrom_device_info *cdi, if (!CDROM_CAN(CDC_SELECT_DISC) || (arg == CDSL_CURRENT || arg == CDSL_NONE)) return cdi->ops->drive_status(cdi, CDSL_CURRENT); - if (((int)arg >= cdi->capacity)) + if (arg >= cdi->capacity) return -EINVAL; return cdrom_slot_status(cdi, arg); }