[PATCH 3.19.y-ckt 003/155] [media] media/vivid-osd: fix info leak in ioctl

From: Kamal Mostafa
Date: Thu Nov 12 2015 - 19:08:26 EST

3.19.8-ckt10 -stable review patch. If anyone has any objections, please let me know.


From: =?UTF-8?q?Salva=20Peir=C3=B3?= <speirofr@xxxxxxxxx>

commit eda98796aff0d9bf41094b06811f5def3b4c333c upstream.

The vivid_fb_ioctl() code fails to initialize the 16 _reserved bytes of
struct fb_vblank after the ->hcount member. Add an explicit
memset(0) before filling the structure to avoid the info leak.

Signed-off-by: Salva Peirà <speirofr@xxxxxxxxx>
Signed-off-by: Hans Verkuil <hans.verkuil@xxxxxxxxx>
Signed-off-by: Mauro Carvalho Chehab <mchehab@xxxxxxxxxxxxxxx>
Reference: CVE-2015-7884
Signed-off-by: Kamal Mostafa <kamal@xxxxxxxxxxxxx>
drivers/media/platform/vivid/vivid-osd.c | 1 +
1 file changed, 1 insertion(+)

diff --git a/drivers/media/platform/vivid/vivid-osd.c b/drivers/media/platform/vivid/vivid-osd.c
index 084d346..e15eef6 100644
--- a/drivers/media/platform/vivid/vivid-osd.c
+++ b/drivers/media/platform/vivid/vivid-osd.c
@@ -85,6 +85,7 @@ static int vivid_fb_ioctl(struct fb_info *info, unsigned cmd, unsigned long arg)
struct fb_vblank vblank;

+ memset(&vblank, 0, sizeof(vblank));
vblank.count = 0;

To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/