[PATCH] usb: gadget: f_mass_storage: fix null pointer dereference in fsg_common_set_num_buffers()
Jeffin Philip <[email protected]>
| Newsgroups | org.kernel.vger.stable,org.kernel.vger.linux-kernel,org.kernel.vger.linux-usb |
|---|---|
| Message-ID | <[email protected]> |
In fsg_common_set_num_buffers(), n can be 0 as conversion to u8 using kstrtou8() in fsg_opts_num_buffers_store() can return values from _0_ to 255. When passing 0 as "n" value to kzalloc_objs, it can return a ZERO_SIZE_PTR, which passes the null check for buffhds. This leads to a null pointer dereference later in bh->next in the do while loop. Fix this by adding a check for n = 0 case and returning -EINVAL if n is 0. Reported-by: [email protected] Closes: https://syzkaller.appspot.com/bug?extid=791be35f1fbcc85d06d7 Fixes: fe5a6c48fd95 ("usb: gadget: storage: get rid of fsg_num_buffers_validate()") Cc: [email protected] Signed-off-by: Jeffin Philip <[email protected]> --- drivers/usb/gadget/function/f_mass_storage.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/drivers/usb/gadget/function/f_mass_storage.c b/drivers/usb/gadget/function/f_mass_storage.c index a50743caf083..640d3bcb7bf0 100644 --- a/drivers/usb/gadget/function/f_mass_storage.c +++ b/drivers/usb/gadget/function/f_mass_storage.c @@ -2747,6 +2747,9 @@ int fsg_common_set_num_buffers(struct fsg_common *common, unsigned int n) struct fsg_buffhd *bh, *buffhds; int i; + if (!n) + return -EINVAL; + buffhds = kzalloc_objs(*buffhds, n); if (!buffhds) return -ENOMEM; -- 2.55.0