Files
twx-linux/include/linux
Vladis Dronov 64a9f5f2e4 HID: debug: fix the ring buffer implementation
commit 13054abbaa upstream.

Ring buffer implementation in hid_debug_event() and hid_debug_events_read()
is strange allowing lost or corrupted data. After commit 717adfdaf1
("HID: debug: check length before copy_to_user()") it is possible to enter
an infinite loop in hid_debug_events_read() by providing 0 as count, this
locks up a system. Fix this by rewriting the ring buffer implementation
with kfifo and simplify the code.

This fixes CVE-2019-3819.

v2: fix an execution logic and add a comment
v3: use __set_current_state() instead of set_current_state()

Backport to v4.9: some tree-wide patches are missing in v4.9 so
cherry-pick relevant pieces from:
 * 6396bb2215 ("treewide: kzalloc() -> kcalloc()")
 * a9a08845e9 ("vfs: do bulk POLL* -> EPOLL* replacement")
 * 174cd4b1e5 ("sched/headers: Prepare to move signal wakeup & sigpending
   methods from <linux/sched.h> into <linux/sched/signal.h>")

Link: https://bugzilla.redhat.com/show_bug.cgi?id=1669187
Cc: stable@vger.kernel.org # v4.18+
Fixes: cd667ce247 ("HID: use debugfs for events/reports dumping")
Fixes: 717adfdaf1 ("HID: debug: check length before copy_to_user()")
Signed-off-by: Vladis Dronov <vdronov@redhat.com>
Reviewed-by: Oleg Nesterov <oleg@redhat.com>
Signed-off-by: Benjamin Tissoires <benjamin.tissoires@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2019-02-15 08:07:39 +01:00
..
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
2017-10-08 10:26:06 +02:00
…
…
2018-04-24 09:34:18 +02:00
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
2017-06-14 15:06:00 +02:00
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
2018-02-28 10:18:33 +01:00
…
…
2017-07-15 12:16:11 +02:00
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
2017-05-14 14:00:22 +02:00
…
…
2017-07-12 15:01:02 +02:00
…
…
…
…
…
…
…
…
…
…
…
…
2017-08-06 18:59:43 -07:00
…
…
…
…
…
…
…
…
…
…
…
…
2018-04-24 09:34:12 +02:00
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
2016-10-20 15:51:28 +11:00
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
2018-10-10 08:53:18 +02:00
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
2017-08-24 17:12:19 -07:00
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
2016-10-19 11:36:22 -06:00
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
2018-09-09 20:01:20 +02:00
…
…
…
…
2017-08-24 17:12:21 -07:00
…
2016-10-14 11:36:59 -07:00
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
2017-08-30 10:21:40 +02:00
2019-01-31 08:12:33 +01:00
…
…
…
…
…
…
…
…
…
…
…
2016-10-05 18:23:36 -04:00
…
…
…
…
…
…
…
…
…
…
…
…
…
2017-01-19 20:17:59 +01:00
…
…
…
…
…
…
…
…
2018-11-13 11:17:02 -08:00
…
…
…
…
…
…
…
…
…
…
…
…
…
…
2018-11-27 16:09:41 +01:00
…
…
…
…
2017-04-21 09:31:21 +02:00
…
…
…
…
…
…
…
…
…
…
2017-12-25 14:23:37 +01:00
…
…
…
…
…
…
…
…
…
…
…
…
2018-12-05 19:42:42 +01:00
…
…
…
…
…
…
…
…