On Wed, 10 May 2017, Johan Hovold wrote:

> A SuperSpeed hub descriptor does not have any variable-length fields so
> bail out when reading a short descriptor.

You mean: bail out when reading a descriptor that is not exactly the
right length.  The existing code already bails out when it reads a
short descriptor.

Alan Stern

> This avoids parsing and leaking two bytes of uninitialised slab data
> through sysfs removable-attributes.
> 
> Fixes: dbe79bbe9dcb ("USB 3.0 Hub Changes")
> Cc: stable <[email protected]>     # 2.6.39
> Cc: John Youn <[email protected]>
> Signed-off-by: Johan Hovold <[email protected]>
> ---
>  drivers/usb/core/hub.c | 8 ++++++--
>  1 file changed, 6 insertions(+), 2 deletions(-)
> 
> diff --git a/drivers/usb/core/hub.c b/drivers/usb/core/hub.c
> index 9dca59ef18b3..3ff1e9f89f2d 100644
> --- a/drivers/usb/core/hub.c
> +++ b/drivers/usb/core/hub.c
> @@ -380,8 +380,12 @@ static int get_hub_descriptor(struct usb_device *hdev, 
> void *data)
>                       USB_REQ_GET_DESCRIPTOR, USB_DIR_IN | USB_RT_HUB,
>                       dtype << 8, 0, data, size,
>                       USB_CTRL_GET_TIMEOUT);
> -             if (ret >= (USB_DT_HUB_NONVAR_SIZE + 2))
> +             if (hub_is_superspeed(hdev)) {
> +                     if (ret == size)
> +                             return ret;
> +             } else if (ret >= (USB_DT_HUB_NONVAR_SIZE + 2)) {
>                       return ret;
> +             }
>       }
>       return -EINVAL;
>  }
> @@ -1321,7 +1325,7 @@ static int hub_configure(struct usb_hub *hub,
>  
>       /* Request the entire hub descriptor.
>        * hub->descriptor can handle USB_MAXCHILDREN ports,
> -      * but the hub can/will return fewer bytes here.
> +      * but a (non-SS) hub can/will return fewer bytes here.
>        */
>       ret = get_hub_descriptor(hdev, hub->descriptor);
>       if (ret < 0) {
> 

--
To unsubscribe from this list: send the line "unsubscribe linux-usb" in
the body of a message to [email protected]
More majordomo info at  http://vger.kernel.org/majordomo-info.html

Reply via email to