| Age | Commit message (Collapse) | Author |
|
git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/tty
Pull tty/serial fixes from Greg KH:
"Here are some small tty/serial driver fixes for 7.3-rc6. Nothing major
here, just lots of small fixes for reported issues, some of them very
long-standing:
- tty hangup fixes that have been there since the BKL days and kept
tripping people up over time.
- vt selection bugfix
- other vt bugfixes (memory leaks and screen update fixes)
- n_gsm bugfix
- qcom-geni serial driver bugfix
- 8250 serial driver bugfixes
- other tiny serial driver fixes
All of these have been in linux-next, the last few only a few days but
testing here seems solid (this pull request was generated on that
tree)"
* tag 'tty-7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/tty: (37 commits)
tty: add missing driver flag kernel-doc colon
vt: selection: Fix unsigned underflow and slab-out-of-bounds read in paste_selection()
vt: skip screen update for DEC alignment test on backgroup consoles
vc_screen: reload vc pointer before if (ret) in vcs_write() to avoid UAF
serial: sc16is7xx: reduce TX refill rate with half-FIFO trigger
serial: sc16is7xx: refill TX FIFO below trigger using fresh TXLVL
serial: tegra: don't clear the Tx FIFO on an Rx-only reset
serial: sc16is7xx: fix TX gap caused by kfifo circular buffer wrap-around
tty: fix saved termios reset race
tty: serial: mpc52xx_uart: move static declarations up.
tty: serial: max3100: shut down timer before freeing port
tty: add break_wait kernel-doc
serial: qcom-geni: keep registered console runtime active
serial: qcom-geni: Fix unbalanced runtime PM resume for no_console_suspend
serial: qcom-geni: avoid unused-function warning
tty: serial: qcom_geni_serial: Keep console RX functional after deep idle
soc: qcom: geni-se: Correct QUP Core ICC vote constants
serial: 8250_bcm7271: fix use-after-free in brcmuart_remove()
serial: vt8500: Fix clock reference leak in vt8500_serial_probe()
kgdboc: Fix tty driver reference leak in configure_kgdboc()
...
|
|
Resetting saved termios state on device registration is needed where a
minor number can be reused for an entirely different device and where
the old settings may prevent the port from even being opened (e.g. when
CLOCAL is not set).
Not all TTY drivers guarantee that the minor number is no longer in use
when registering devices however, something which can lead to a
use-after-free when closing a TTY (and saving its termios) races with
re-registration.
Add a new TTY_DRIVER_RESET_SAVED_TERMIOS flag to request that any saved
termios state is reset on registration and only set it for drivers that
make sure that the minor number is no longer in use.
Fixes: 93857edd9829 ("tty: reset termios state on device registration")
Reported-by: Chengfeng Ye <nicoyip.dev@gmail.com>
Link: https://lore.kernel.org/20260926184154.3017929-1-nicoyip.dev@gmail.com
Cc: stable@kernel.org # 4.12
Signed-off-by: Johan Hovold <johan@kernel.org>
Link: https://patch.msgid.link/20260930131845.1809256-1-johan@kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
|
|
Avoid a compilation error so that they're not used before being
declared.
Fixes: 4d105880666a ("tty: serial: mpc52xx_uart: add bounds check for psc_num array index")
Reported-by: kernel test robot <lkp@intel.com>
Closes: https://lore.kernel.org/oe-kbuild-all/202609260356.tJWbd1WU-lkp@intel.com/
Signed-off-by: Rosen Penev <rosenp@gmail.com>
Link: https://patch.msgid.link/20260927203501.14105-1-rosenp@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
|
|
generic_set_cmd() and generic_get_cmd() use the low nibble of
ctrl->bRequest as an index into con->data[]:
u8 cmd = (ctrl->bRequest & 0x0F); /* 0 .. 15 */
...
con->data[cmd] = value; /* OOB when cmd >= 5 */
struct usb_audio_control (include/linux/usb/audio.h) declares data as
a 5-element array, so indices 5 through 15 write (or read) up to 44
bytes past the end of the array on the heap.
A malicious USB host can craft a class-specific SET_CUR / GET_CUR
request with an arbitrary bRequest value, triggering the out-of-bounds
access from an IRQ completion handler with no further preconditions.
Add an ARRAY_SIZE() guard to both functions.
Fixes: c47d7b09891a ("USB: audio: add USB audio class definitions")
Cc: stable <stable@kernel.org>
Reviewed-by: Weibin Liu <liuwb@xiaopeng.com>
Signed-off-by: Liu Chao <liuc63@xiaopeng.com>
Reviewed-by: Ivy Lopez <skunkolee@gmail.com>
Link: https://patch.msgid.link/20260921072551.3708191-1-liuc63@xiaopeng.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
|