From: Dan Carpenter Date: Tue, 6 May 2014 19:50:12 +0000 (-0700) Subject: agp: info leak in agpioc_info_wrap() X-Git-Tag: MMI-PSA29.97-13-9~12244^2 X-Git-Url: https://git.stricted.de/?a=commitdiff_plain;h=3ca9e5d36afb5c0a6ee6ceee69e507370beb59c6;p=GitHub%2FMotorolaMobilityLLC%2Fkernel-slsi.git agp: info leak in agpioc_info_wrap() On 64 bit systems the agp_info struct has a 4 byte hole between ->agp_mode and ->aper_base. We need to clear it to avoid disclosing stack information to userspace. Signed-off-by: Dan Carpenter Cc: David Airlie Cc: Daniel Vetter Signed-off-by: Andrew Morton Signed-off-by: Linus Torvalds --- diff --git a/drivers/char/agp/frontend.c b/drivers/char/agp/frontend.c index 8121b4c70ede..b29703324e94 100644 --- a/drivers/char/agp/frontend.c +++ b/drivers/char/agp/frontend.c @@ -730,6 +730,7 @@ static int agpioc_info_wrap(struct agp_file_private *priv, void __user *arg) agp_copy_info(agp_bridge, &kerninfo); + memset(&userinfo, 0, sizeof(userinfo)); userinfo.version.major = kerninfo.version.major; userinfo.version.minor = kerninfo.version.minor; userinfo.bridge_id = kerninfo.device->vendor |