From: Geert Uytterhoeven Date: Tue, 10 Apr 2018 13:21:45 +0000 (+0200) Subject: ARM: amba: Don't read past the end of sysfs "driver_override" buffer X-Git-Url: https://git.stricted.de/?a=commitdiff_plain;h=f671ee8de31a3c2702250e64e5f18ebceb21f1e6;p=GitHub%2FLineageOS%2Fandroid_kernel_motorola_exynos9610.git ARM: amba: Don't read past the end of sysfs "driver_override" buffer commit d2ffed5185df9d8d9ccd150e4340e3b6f96a8381 upstream. When printing the driver_override parameter when it is 4095 and 4094 bytes long, the printing code would access invalid memory because we need count + 1 bytes for printing. Cfr. commits 4efe874aace57dba ("PCI: Don't read past the end of sysfs "driver_override" buffer") and bf563b01c2895a4b ("driver core: platform: Don't read past the end of "driver_override" buffer"). Fixes: 3cf385713460eb2b ("ARM: 8256/1: driver coamba: add device binding path 'driver_override'") Signed-off-by: Geert Uytterhoeven Reviewed-by: Todd Kjos Cc: stable Signed-off-by: Greg Kroah-Hartman --- diff --git a/drivers/amba/bus.c b/drivers/amba/bus.c index 8c7d0c64ebe0..8a99fbe5759f 100644 --- a/drivers/amba/bus.c +++ b/drivers/amba/bus.c @@ -84,7 +84,8 @@ static ssize_t driver_override_store(struct device *_dev, struct amba_device *dev = to_amba_device(_dev); char *driver_override, *old, *cp; - if (count > PATH_MAX) + /* We need to keep extra room for a newline */ + if (count >= (PAGE_SIZE - 1)) return -EINVAL; driver_override = kstrndup(buf, count, GFP_KERNEL);