Commit 35f977e3 authored by Al Viro's avatar Al Viro Committed by Kamal Mostafa

staging: lustre: echo_copy.._lsm() dereferences userland pointers directly

commit 9225c0b7 upstream.

missing get_user()
Signed-off-by: default avatarAl Viro <viro@zeniv.linux.org.uk>
Signed-off-by: default avatarGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: default avatarKamal Mostafa <kamal@canonical.com>
parent caf5502e
...@@ -1260,6 +1260,7 @@ static int ...@@ -1260,6 +1260,7 @@ static int
echo_copyout_lsm (struct lov_stripe_md *lsm, void *_ulsm, int ulsm_nob) echo_copyout_lsm (struct lov_stripe_md *lsm, void *_ulsm, int ulsm_nob)
{ {
struct lov_stripe_md *ulsm = _ulsm; struct lov_stripe_md *ulsm = _ulsm;
struct lov_oinfo **p;
int nob, i; int nob, i;
nob = offsetof (struct lov_stripe_md, lsm_oinfo[lsm->lsm_stripe_count]); nob = offsetof (struct lov_stripe_md, lsm_oinfo[lsm->lsm_stripe_count]);
...@@ -1269,9 +1270,10 @@ echo_copyout_lsm (struct lov_stripe_md *lsm, void *_ulsm, int ulsm_nob) ...@@ -1269,9 +1270,10 @@ echo_copyout_lsm (struct lov_stripe_md *lsm, void *_ulsm, int ulsm_nob)
if (copy_to_user (ulsm, lsm, sizeof(*ulsm))) if (copy_to_user (ulsm, lsm, sizeof(*ulsm)))
return -EFAULT; return -EFAULT;
for (i = 0; i < lsm->lsm_stripe_count; i++) { for (i = 0, p = lsm->lsm_oinfo; i < lsm->lsm_stripe_count; i++, p++) {
if (copy_to_user (ulsm->lsm_oinfo[i], lsm->lsm_oinfo[i], struct lov_oinfo __user *up;
sizeof(lsm->lsm_oinfo[0]))) if (get_user(up, ulsm->lsm_oinfo + i) ||
copy_to_user(up, *p, sizeof(struct lov_oinfo)))
return -EFAULT; return -EFAULT;
} }
return 0; return 0;
...@@ -1279,9 +1281,10 @@ echo_copyout_lsm (struct lov_stripe_md *lsm, void *_ulsm, int ulsm_nob) ...@@ -1279,9 +1281,10 @@ echo_copyout_lsm (struct lov_stripe_md *lsm, void *_ulsm, int ulsm_nob)
static int static int
echo_copyin_lsm (struct echo_device *ed, struct lov_stripe_md *lsm, echo_copyin_lsm (struct echo_device *ed, struct lov_stripe_md *lsm,
void *ulsm, int ulsm_nob) struct lov_stripe_md __user *ulsm, int ulsm_nob)
{ {
struct echo_client_obd *ec = ed->ed_ec; struct echo_client_obd *ec = ed->ed_ec;
struct lov_oinfo **p;
int i; int i;
if (ulsm_nob < sizeof (*lsm)) if (ulsm_nob < sizeof (*lsm))
...@@ -1296,12 +1299,10 @@ echo_copyin_lsm (struct echo_device *ed, struct lov_stripe_md *lsm, ...@@ -1296,12 +1299,10 @@ echo_copyin_lsm (struct echo_device *ed, struct lov_stripe_md *lsm,
((__u64)lsm->lsm_stripe_size * lsm->lsm_stripe_count > ~0UL)) ((__u64)lsm->lsm_stripe_size * lsm->lsm_stripe_count > ~0UL))
return -EINVAL; return -EINVAL;
for (i = 0, p = lsm->lsm_oinfo; i < lsm->lsm_stripe_count; i++, p++) {
for (i = 0; i < lsm->lsm_stripe_count; i++) { struct lov_oinfo __user *up;
if (copy_from_user(lsm->lsm_oinfo[i], if (get_user(up, ulsm->lsm_oinfo + i) ||
((struct lov_stripe_md *)ulsm)-> \ copy_from_user(*p, up, sizeof(struct lov_oinfo)))
lsm_oinfo[i],
sizeof(lsm->lsm_oinfo[0])))
return -EFAULT; return -EFAULT;
} }
return 0; return 0;
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment