Files
twx-linux/drivers/scsi
Jann Horn 9a737329c7 scsi: sg: mitigate read/write abuse
commit 26b5b874af upstream.

As Al Viro noted in commit 128394eff3 ("sg_write()/bsg_write() is not fit
to be called under KERNEL_DS"), sg improperly accesses userspace memory
outside the provided buffer, permitting kernel memory corruption via
splice().  But it doesn't just do it on ->write(), also on ->read().

As a band-aid, make sure that the ->read() and ->write() handlers can not
be called in weird contexts (kernel context or credentials different from
file opener), like for ib_safe_file_access().

If someone needs to use these interfaces from different security contexts,
a new interface should be written that goes through the ->ioctl() handler.

I've mostly copypasted ib_safe_file_access() over as sg_safe_file_access()
because I couldn't find a good common header - please tell me if you know a
better way.

[mkp: s/_safe_/_check_/]

Fixes: 1da177e4c3 ("Linux-2.6.12-rc2")
Cc: <stable@vger.kernel.org>
Signed-off-by: Jann Horn <jannh@google.com>
Acked-by: Douglas Gilbert <dgilbert@interlog.com>
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2018-07-11 16:03:48 +02:00
..
2016-04-12 09:08:39 -07:00
2017-12-25 14:22:14 +01:00
…
2015-11-09 17:11:57 -08:00
2017-03-18 19:09:58 +08:00
…
2015-11-12 07:06:18 -05:00
…
…
…
…
…
2016-07-27 09:47:39 -07:00
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
2018-02-25 11:03:44 +01:00
…
…
…
…
2015-11-09 17:11:57 -08:00
…
2015-11-09 16:32:14 -08:00
…
…
…
…
2015-12-03 09:32:33 -08:00
2018-01-23 19:50:15 +01:00
2017-12-20 10:04:55 +01:00
…
…
…
…
…
2018-03-22 09:23:21 +01:00
2015-11-09 19:32:41 -05:00
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
2015-11-12 07:06:18 -05:00
…
…
…
…
…
2018-03-22 09:23:29 +01:00
2016-10-28 03:01:31 -04:00
2015-11-09 17:11:57 -08:00
…
…
2018-07-11 16:03:48 +02:00
…
2018-02-25 11:03:44 +01:00
…
2015-12-03 09:32:33 -08:00
…
2015-11-09 17:42:19 -08:00
…
…
…
…
…
…
…
…
…