From patchwork Thu Jan 7 14:32:06 2021 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Greg Kroah-Hartman X-Patchwork-Id: 358245 Delivered-To: patch@linaro.org Received: by 2002:a02:85a7:0:0:0:0:0 with SMTP id d36csp538727jai; Thu, 7 Jan 2021 06:37:52 -0800 (PST) X-Google-Smtp-Source: ABdhPJynVUAxxYwkBc/HKJgnU3QlC3TG3vi5F0eVzoZMcq+NR7uqRCupQ8FOw5lNz6EqVaGLO1bM X-Received: by 2002:a05:6402:139a:: with SMTP id b26mr1890624edv.47.1610030272357; Thu, 07 Jan 2021 06:37:52 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1610030272; cv=none; d=google.com; s=arc-20160816; b=thgkdRpKhmct6VDYCi8D75C19WUE7Wu+cyu6SOIUih7eBvzUdulZdirYHAdk3FaHI3 rw3PQX3xg/sCcgBCpiND66c0J9m0sKvb6cQlxEi/7lmj2uu/g5ACjFOQVccdEbzG0q02 /GFzkD8NfUSIhd+eR0pEUHt+8J231r77dkD1g0obPzNWehIwEDSgdARX/jPwwKymyodU 3+F8t1c0zWrqUxT6wh6Vbk2Hb+2NTOVxCNPKOlQvch9NZth5zJ7fAAS65vecxkl7GZN4 Pw/0fzBd9V/pM7NpzFEkSWCrJgKncEv59PiqhBN7lalNPCG2oxXHbcXftocHoM9uar2d Rr3g== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :user-agent:references:in-reply-to:message-id:date:subject:cc:to :from:dkim-signature; bh=pd6N0dYV9Vo/HKOyHagu7Bva4p/fCbP5h7gFkl/6mw4=; b=s0qI+jgCstHW1VKOOB0IaaZS8InToUEWbju6OQyz+RR3eUSjeCSy5s+ldqhrMlGXYw TrWF95UeYzFxmM7qDIOEYfvo2TSR8WnVzl4AsHeqAVeGhaNWFNkG3IznwwYCb7GHzTfn Dg0gWL6dOu4mEeSh5kxPlUjgD64T9Z7YRJTsC5b7b0of6IXmWmMFCr3R6dMN3lmrLELc NZkSkyiiHfVSRjPuCGQLdfW4nyHMswgENsYM9mZ1Oo/6OzYZ7oxDnXmThmCGjB8gbssu PFzugW1pDLgaZUP2UrXHaPBUV29fSpMAyUvsUhehiV2/q5nb8r3ENa+os7adyOwUbktv bd6Q== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@linuxfoundation.org header.s=korg header.b=YWC8F9g+; spf=pass (google.com: domain of stable-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=stable-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=linuxfoundation.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id a11si2195544eje.119.2021.01.07.06.37.52; Thu, 07 Jan 2021 06:37:52 -0800 (PST) Received-SPF: pass (google.com: domain of stable-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=pass header.i=@linuxfoundation.org header.s=korg header.b=YWC8F9g+; spf=pass (google.com: domain of stable-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=stable-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=linuxfoundation.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1729117AbhAGOhC (ORCPT + 14 others); Thu, 7 Jan 2021 09:37:02 -0500 Received: from mail.kernel.org ([198.145.29.99]:45346 "EHLO mail.kernel.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1729228AbhAGOcK (ORCPT ); Thu, 7 Jan 2021 09:32:10 -0500 Received: by mail.kernel.org (Postfix) with ESMTPSA id 18C3E23370; Thu, 7 Jan 2021 14:31:48 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=linuxfoundation.org; s=korg; t=1610029909; bh=RFw+n++0ZHliEK3pgZhexrztSDm+0bCdgrR26y+fNP4=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=YWC8F9g+Y+0mw60shu+PhhDJ59fPRC6wOoYzeazAcmOOS6NdZbWH5PtftGv/IKEWU YemjG1cwzrGKLnX3ufPMtHwkOAOgoGo4L1OHJVxAdiYNJMJ1hYCaw9Pbs0KLA4gEBm aM9HTK7m7ZYfvnwhvBF9ib8HbAo6bSRqchG5zxnc= From: Greg Kroah-Hartman To: linux-kernel@vger.kernel.org Cc: Greg Kroah-Hartman , stable@vger.kernel.org, Lars-Peter Clausen , Jonathan Cameron , Alexandru Ardelean , Daniel Baluta , Daniel Baluta , Stable@vger.kernel.org, Sudip Mukherjee Subject: [PATCH 4.19 6/8] iio:imu:bmi160: Fix alignment and data leak issues Date: Thu, 7 Jan 2021 15:32:06 +0100 Message-Id: <20210107143048.450324345@linuxfoundation.org> X-Mailer: git-send-email 2.30.0 In-Reply-To: <20210107143047.586006010@linuxfoundation.org> References: <20210107143047.586006010@linuxfoundation.org> User-Agent: quilt/0.66 MIME-Version: 1.0 Precedence: bulk List-ID: X-Mailing-List: stable@vger.kernel.org From: Jonathan Cameron commit 7b6b51234df6cd8b04fe736b0b89c25612d896b8 upstream One of a class of bugs pointed out by Lars in a recent review. iio_push_to_buffers_with_timestamp assumes the buffer used is aligned to the size of the timestamp (8 bytes). This is not guaranteed in this driver which uses an array of smaller elements on the stack. As Lars also noted this anti pattern can involve a leak of data to userspace and that indeed can happen here. We close both issues by moving to a suitable array in the iio_priv() data with alignment explicitly requested. This data is allocated with kzalloc() so no data can leak apart from previous readings. In this driver, depending on which channels are enabled, the timestamp can be in a number of locations. Hence we cannot use a structure to specify the data layout without it being misleading. Fixes: 77c4ad2d6a9b ("iio: imu: Add initial support for Bosch BMI160") Reported-by: Lars-Peter Clausen Signed-off-by: Jonathan Cameron Reviewed-by: Alexandru Ardelean Cc: Daniel Baluta Cc: Daniel Baluta Cc: Link: https://lore.kernel.org/r/20200920112742.170751-6-jic23@kernel.org [sudip: adjust context and use bmi160_data in old location] Signed-off-by: Sudip Mukherjee Signed-off-by: Greg Kroah-Hartman --- drivers/iio/imu/bmi160/bmi160_core.c | 13 +++++++++---- 1 file changed, 9 insertions(+), 4 deletions(-) --- a/drivers/iio/imu/bmi160/bmi160_core.c +++ b/drivers/iio/imu/bmi160/bmi160_core.c @@ -110,6 +110,13 @@ enum bmi160_sensor_type { struct bmi160_data { struct regmap *regmap; + /* + * Ensure natural alignment for timestamp if present. + * Max length needed: 2 * 3 channels + 4 bytes padding + 8 byte ts. + * If fewer channels are enabled, less space may be needed, as + * long as the timestamp is still aligned to 8 bytes. + */ + __le16 buf[12] __aligned(8); }; const struct regmap_config bmi160_regmap_config = { @@ -385,8 +392,6 @@ static irqreturn_t bmi160_trigger_handle struct iio_poll_func *pf = p; struct iio_dev *indio_dev = pf->indio_dev; struct bmi160_data *data = iio_priv(indio_dev); - __le16 buf[12]; - /* 2 sens x 3 axis x __le16 + 2 x __le16 pad + 4 x __le16 tstamp */ int i, ret, j = 0, base = BMI160_REG_DATA_MAGN_XOUT_L; __le16 sample; @@ -396,10 +401,10 @@ static irqreturn_t bmi160_trigger_handle &sample, sizeof(sample)); if (ret < 0) goto done; - buf[j++] = sample; + data->buf[j++] = sample; } - iio_push_to_buffers_with_timestamp(indio_dev, buf, + iio_push_to_buffers_with_timestamp(indio_dev, data->buf, iio_get_time_ns(indio_dev)); done: iio_trigger_notify_done(indio_dev->trig);