Received: by 10.223.185.116 with SMTP id b49csp1114467wrg; Sat, 3 Mar 2018 16:00:57 -0800 (PST) X-Google-Smtp-Source: AG47ELvwfN7eLsDMrm2uNhZisvnoVcofW65G4ysLXDfKVl0Llv6fUODQf5TVI8RlecR1MC5HuyaD X-Received: by 2002:a17:902:b086:: with SMTP id p6-v6mr7135928plr.67.1520121657289; Sat, 03 Mar 2018 16:00:57 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1520121657; cv=none; d=google.com; s=arc-20160816; b=ubeP4VNUzA18gBCUkSH5DY09q6+0sXiJDtJgiuplLpQeeephAxUOSpeHOKJGsjJ/LA j18WfpjREhlQjW5M5ps/JEGJFNQfmCmMRspGGxjKR0ZzWyAonf7vQo/SrjhYuF2rq12C QHwoweqgABrj+G4A66a9Jy3enEtVFt+2qwneP/RXXIpywxW9SkMNABPUg3nTE1xeQFF+ pUX93/WxFNjKTPNrFpU7UGbqkNqwA+8y1bjZ21DSW5C/jAfagmZkajoWSgy93ZrHMWH2 pemYGm40lECsS0Zpx/GVDgNx17pgL9szzcW/tgcTWdHLvUPw3bTM/mxN5c7EL7Qz1Fum ALWQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:mime-version:content-transfer-encoding :spamdiagnosticmetadata:spamdiagnosticoutput:content-language :accept-language:in-reply-to:references:message-id:date:thread-index :thread-topic:subject:cc:to:from:dkim-signature :arc-authentication-results; bh=40RStWIE4sR3lWtybcx1izvIPtRftbpA308caXeku50=; b=ihcZ1E5wRrU+f60/MGmzJMaYhzwE5TLbuqW6hvoRdoo6Hi3ymaRw/WBKSP4Z0D9EUl Nul7SmHbM1AnqLjppbz1RD8hpgVry0AEJ+Y3BFEUrUyvyKGqQQqIXrVi3Qqm0v0E6SJP wyo6fHKdO+oY8NE+8/4dK57FccKqZyR/Adb8QtB6kri6P9qIxbQsHSEVrXzbZknN3Mjo jYNC6Q756dMS3bRA7VXr7NS54V4NgYeobJWwcuwfCeOfbyy3zXNlASqZT/mblxA2hO4b q56jiy+MTizRy6aU8mNmarRVK4ffNCM5JDk2Nry/znuOgDz0CCy+vrj4gfF2uT7ItaNU Cs0w== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@microsoft.com header.s=selector1 header.b=Wpzpb/r8; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=microsoft.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id s185si6182794pgc.718.2018.03.03.16.00.43; Sat, 03 Mar 2018 16:00:57 -0800 (PST) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@microsoft.com header.s=selector1 header.b=Wpzpb/r8; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=microsoft.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1752583AbeCCX7G (ORCPT + 99 others); Sat, 3 Mar 2018 18:59:06 -0500 Received: from mail-by2nam03on0115.outbound.protection.outlook.com ([104.47.42.115]:54496 "EHLO NAM03-BY2-obe.outbound.protection.outlook.com" rhost-flags-OK-OK-OK-FAIL) by vger.kernel.org with ESMTP id S933465AbeCCWcQ (ORCPT ); Sat, 3 Mar 2018 17:32:16 -0500 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=40RStWIE4sR3lWtybcx1izvIPtRftbpA308caXeku50=; b=Wpzpb/r85pE4bUUKOCL+jNFT4SGpZ5HhYepeST9X8hpOY/yp+Cep+r1Ou61ZByNV0jbI8FZTzRWOAwceIEH2OLkyOKqCUOZ3YJu/pWvTIUDoOwIpOqHfBpd4KwH5qlcau95HN2SkEcm8uf4r3kOyqg8xlwiMcHVRZQFY6BpL2Oc= Received: from MW2PR2101MB1034.namprd21.prod.outlook.com (52.132.149.10) by MW2PR2101MB1036.namprd21.prod.outlook.com (52.132.149.12) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.567.3; Sat, 3 Mar 2018 22:32:12 +0000 Received: from MW2PR2101MB1034.namprd21.prod.outlook.com ([fe80::1d56:338f:e2b:cec0]) by MW2PR2101MB1034.namprd21.prod.outlook.com ([fe80::1d56:338f:e2b:cec0%3]) with mapi id 15.20.0567.006; Sat, 3 Mar 2018 22:32:12 +0000 From: Sasha Levin To: "linux-kernel@vger.kernel.org" , "stable@vger.kernel.org" CC: Johan Hovold , Daniel Drake , Kalle Valo , Sasha Levin Subject: [PATCH AUTOSEL for 4.9 050/219] zd1211rw: fix NULL-deref at probe Thread-Topic: [PATCH AUTOSEL for 4.9 050/219] zd1211rw: fix NULL-deref at probe Thread-Index: AQHTsz7xUpsvD/qn3kKhTNGMXldAhg== Date: Sat, 3 Mar 2018 22:28:24 +0000 Message-ID: <20180303222716.26640-50-alexander.levin@microsoft.com> References: <20180303222716.26640-1-alexander.levin@microsoft.com> In-Reply-To: <20180303222716.26640-1-alexander.levin@microsoft.com> Accept-Language: en-US Content-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: x-originating-ip: [52.168.54.252] x-ms-publictraffictype: Email x-microsoft-exchange-diagnostics: 1;MW2PR2101MB1036;7:61Bh2X2Bs0Qr129K5frKlCANclTnt4Lsm3h4/cmwoC4AR+GiH+Sb44U2NhkO38tD/R5CvhTzmbpJXVyYNN6kd13fnvYxNUz6rKqKDwFJddqS2RD7X9a6WHhDzxvPGcbbikvNZAiDZ5J2rMudB09ZNtFOaRNo8+VRiCoppO2b5BMTl83sIwtLNkjHjP7FnOAY5vuv9xPKJg84q9T3GqAiPpQy5JJtEMOJ4ErrFgvwEFPdXRsoLyAoPOg6Pr3oKFJO x-ms-office365-filtering-ht: Tenant x-ms-office365-filtering-correlation-id: 579066c7-a2bf-468a-9002-08d581569c27 x-microsoft-antispam: UriScan:;BCL:0;PCL:0;RULEID:(7020095)(4652020)(4534165)(4627221)(201703031133081)(201702281549075)(48565401081)(5600026)(4604075)(3008032)(2017052603307)(7193020);SRVR:MW2PR2101MB1036; x-ms-traffictypediagnostic: MW2PR2101MB1036: authentication-results: spf=none (sender IP is ) smtp.mailfrom=Alexander.Levin@microsoft.com; x-microsoft-antispam-prvs: x-exchange-antispam-report-test: UriScan:(28532068793085)(89211679590171); x-exchange-antispam-report-cfa-test: BCL:0;PCL:0;RULEID:(8211001083)(61425038)(6040501)(2401047)(8121501046)(5005006)(93006095)(93001095)(3231220)(944501244)(52105095)(3002001)(10201501046)(6055026)(61426038)(61427038)(6041288)(20161123562045)(20161123564045)(20161123558120)(20161123560045)(201703131423095)(201702281528075)(20161123555045)(201703061421075)(201703061406153)(6072148)(201708071742011);SRVR:MW2PR2101MB1036;BCL:0;PCL:0;RULEID:;SRVR:MW2PR2101MB1036; x-forefront-prvs: 0600F93FE1 x-forefront-antispam-report: SFV:NSPM;SFS:(10019020)(396003)(366004)(39380400002)(346002)(376002)(39860400002)(199004)(189003)(10290500003)(81166006)(5660300001)(107886003)(8936002)(81156014)(3846002)(6506007)(2906002)(8676002)(3280700002)(72206003)(76176011)(4326008)(478600001)(6116002)(6486002)(53936002)(1076002)(68736007)(6512007)(102836004)(2501003)(66066001)(3660700001)(5250100002)(6436002)(105586002)(86612001)(36756003)(316002)(7736002)(97736004)(26005)(186003)(110136005)(305945005)(22452003)(86362001)(99286004)(6666003)(25786009)(106356001)(2900100001)(14454004)(54906003)(10090500001)(2950100002)(22906009)(217873001);DIR:OUT;SFP:1102;SCL:1;SRVR:MW2PR2101MB1036;H:MW2PR2101MB1034.namprd21.prod.outlook.com;FPR:;SPF:None;PTR:InfoNoRecords;A:1;MX:1;LANG:en; received-spf: None (protection.outlook.com: microsoft.com does not designate permitted sender hosts) x-microsoft-antispam-message-info: C7JiQF/lw4Q1uw4PDGoqyKA4d9b3OHoOrCthkHyt+f0VL4w3RlX1/czf85YpDw4M3tY3TEeYtd0S/eOCLQloB/gFTiWs6r/me8U7K14tu0BavXK2S4z9Ab+zrqlmZ9cBg4U7B18nXslVq/0XKq6TlFyLMVlCez2k7ZPSKszkyeU= spamdiagnosticoutput: 1:99 spamdiagnosticmetadata: NSPM Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 X-OriginatorOrg: microsoft.com X-MS-Exchange-CrossTenant-Network-Message-Id: 579066c7-a2bf-468a-9002-08d581569c27 X-MS-Exchange-CrossTenant-originalarrivaltime: 03 Mar 2018 22:28:24.9319 (UTC) X-MS-Exchange-CrossTenant-fromentityheader: Hosted X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47 X-MS-Exchange-Transport-CrossTenantHeadersStamped: MW2PR2101MB1036 Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org From: Johan Hovold [ Upstream commit ca260ece6a57dc7d751e0685f51fa2c55d851873 ] Make sure to check the number of endpoints to avoid dereferencing a NULL-pointer or accessing memory beyond the endpoint array should a malicious device lack the expected endpoints. Fixes: a1030e92c150 ("[PATCH] zd1211rw: Convert installer CDROM device into= WLAN device") Cc: Daniel Drake Signed-off-by: Johan Hovold Signed-off-by: Kalle Valo Signed-off-by: Sasha Levin --- drivers/net/wireless/zydas/zd1211rw/zd_usb.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/drivers/net/wireless/zydas/zd1211rw/zd_usb.c b/drivers/net/wir= eless/zydas/zd1211rw/zd_usb.c index c5effd6c6be9..01ca1d57b3d9 100644 --- a/drivers/net/wireless/zydas/zd1211rw/zd_usb.c +++ b/drivers/net/wireless/zydas/zd1211rw/zd_usb.c @@ -1278,6 +1278,9 @@ static int eject_installer(struct usb_interface *intf= ) u8 bulk_out_ep; int r; =20 + if (iface_desc->desc.bNumEndpoints < 2) + return -ENODEV; + /* Find bulk out endpoint */ for (r =3D 1; r >=3D 0; r--) { endpoint =3D &iface_desc->endpoint[r].desc; --=20 2.14.1