[PATCH] usb-serial: fix oti6858.c segfault in termios handling

Thomas Viehmann <[email protected]>
Newsgroups gmane.linux.usb.devel,gmane.linux.kernel
Message-ID <[email protected]>
The oti6858 usb serial driver should use 
kernel_termios_to_user_termios/
user_termios_to_kernel_termios to avoid segfaults because the kernel
uses a structure differing from that of user space with a different 
size.

Signed-off-by: Thomas Viehmann <[email protected]>
---
I'm don't know the least thing about the type casting (it is lifted
from kobil_sct.c), but I do get better success with the patch...
--- linux-2.6.23-rc1/drivers/usb/serial/oti6858.c.orig
+++ linux-2.6.23-rc1/drivers/usb/serial/oti6858.c
@@ -818,19 +818,22 @@

        switch (cmd) {
                case TCGETS:
-                       if (copy_to_user(user_arg, port->tty->termios,
-                                               sizeof(struct 
ktermios))) {
+                       if (kernel_termios_to_user_termios(
+                                            (struct ktermios __user 
*)arg,
+                                            port->tty->termios))
                                return -EFAULT;
-                       }
                        return 0;

                case TCSETS:
                case TCSETSW:                  case TCSETSF:   -      
                  if (copy_from_user(port->tty->termios, user_arg,
-                                               sizeof(struct 
ktermios))) {
+                       if 
(user_termios_to_kernel_termios(port->tty->termios,
+                                               (struct ktermios 
__user *)arg))
                                return -EFAULT;
-                       }
                        oti6858_set_termios(port, NULL);
                        return 0;

--
Thomas Viehmann, http://thomas.viehmann.net/

-------------------------------------------------------------------------
This SF.net email is sponsored by: Splunk Inc.
Still grepping through log files to find problems?  Stop.
Now Search log events and configuration files using AJAX and a browser.
Download your FREE copy of Splunk now >>  http://get.splunk.com/
_______________________________________________
[email protected]
To unsubscribe, use the last form field at:
https://lists.sourceforge.net/lists/listinfo/linux-usb-devel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.