From f9966e1df3f18830c57b0fd4ff47b33bb98a30e2 Mon Sep 17 00:00:00 2001 From: Edward Adam Davis Date: Fri, 11 Oct 2024 02:37:37 +0000 Subject: [PATCH] USB: usbtmc: prevent kernel-usb-infoleak mainline inclusion from mainline-v6.12-rc1 commit 625fa77151f00c1bd00d34d60d6f2e710b3f9aad category: bugfix bugzilla: https://gitee.com/src-openeuler/kernel/issues/IAVU7U CVE: CVE-2024-47671 Reference: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=625fa77151f00c1bd00d34d60d6f2e710b3f9aad -------------------------------- The syzbot reported a kernel-usb-infoleak in usbtmc_write, we need to clear the structure before filling fields. Fixes: 4ddc645f40e9 ("usb: usbtmc: Add ioctl for vendor specific write") Reported-and-tested-by: syzbot+9d34f80f841e948c3fdb@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=9d34f80f841e948c3fdb Signed-off-by: Edward Adam Davis Cc: stable Link: https://lore.kernel.org/r/tencent_9649AA6EC56EDECCA8A7D106C792D1C66B06@qq.com Signed-off-by: Greg Kroah-Hartman --- drivers/usb/class/usbtmc.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/usb/class/usbtmc.c b/drivers/usb/class/usbtmc.c index 49f59d53b4b2..cf285d43d0c1 100644 --- a/drivers/usb/class/usbtmc.c +++ b/drivers/usb/class/usbtmc.c @@ -724,7 +724,7 @@ static struct urb *usbtmc_create_urb(void) if (!urb) return NULL; - dmabuf = kmalloc(bufsize, GFP_KERNEL); + dmabuf = kzalloc(bufsize, GFP_KERNEL); if (!dmabuf) { usb_free_urb(urb); return NULL; -- Gitee