Received: by 2002:a05:7412:518d:b0:e2:908c:2ebd with SMTP id fn13csp425004rdb; Thu, 5 Oct 2023 09:42:50 -0700 (PDT) X-Google-Smtp-Source: AGHT+IHqePRHNreZtfkzfPGRR69JGRY9Zm2gYpsGs2c742p8PtWsrqIbDBLjiwNhk4pMl+vJLqso X-Received: by 2002:a05:6a00:1954:b0:693:3be8:feba with SMTP id s20-20020a056a00195400b006933be8febamr6907850pfk.19.1696524170062; Thu, 05 Oct 2023 09:42:50 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1696524170; cv=none; d=google.com; s=arc-20160816; b=Pur8VLG6C8KJYRV7KgMv8FjSBK+xlFoTno8QyDpq1APStdC4ogPtagiRadvqEAg5Fy VKcSwjv2RYQb5Exn75EMAyfgytNQtDor2Z+YDfJOwpMmmM4CPIcbTm0AasmeG5pTSKGh VbVAzyFWkOgHeGx+n7JncSvyGF53hhW+kHd7QsntC+VnJxdMGDYrL9bWZ7UMmFfPD7Bd dB/PFAL6Du15OZ34/bK8AAzQYJ+wtktEyuPYhksaF8xr3NRN7YnEA8zTQeb76kYWlvEO OO6kM2jHXhlGxIVUur4t88OOJ4O/l8z9sLSYs9E3jdaK5GBw2MPdUr8PI6SAXem3OUn+ lgIA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-disposition:mime-version:message-id :subject:cc:to:from:date:dkim-signature; bh=TVELeAMbqDGQTgb0H+LdBlcaOEIyA8bnbU3CE39csMo=; fh=AMUrveNiwEwlW/0EHnH+dhuDXrK5Ns17VnVtNbBK2oE=; b=i8nMj6beBOVudMO5DMWaHyg8gh8y18KGZqS05KoqRNhmy/joVZhwU4vpiqTWi1I5kt q5hRDGvJ/xjx8Mlqs0IaGfyiDrKB9t82Rk3aERS4P6Otqbw5JaIhOitUQtdD/d+DgfmB BHdrtw9AqqR/beebO6cZz5mZOBVv9hgV5sMDnORqOkeJwkHqK6DPkMussT2EUyKvN0Rw grAtNG2/m+u4lwzzWTYZShN7tSlWWpEzQShb8mjUJTDwLnFFX5/C0194orUHqSw1EvW1 2GkNHaTIf9SixYebmNd+pGnt/tuhG3c2SDmoYSh27wW6hOUYYahFLZjxfGzWQ1HT9rJV TB2w== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@gmail.com header.s=20230601 header.b=hGMInpkH; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.34 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Return-Path: Received: from howler.vger.email (howler.vger.email. [23.128.96.34]) by mx.google.com with ESMTPS id h5-20020a056a00170500b00690d00d52efsi1824966pfc.264.2023.10.05.09.42.49 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 05 Oct 2023 09:42:50 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.34 as permitted sender) client-ip=23.128.96.34; Authentication-Results: mx.google.com; dkim=pass header.i=@gmail.com header.s=20230601 header.b=hGMInpkH; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.34 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Received: from out1.vger.email (depot.vger.email [IPv6:2620:137:e000::3:0]) by howler.vger.email (Postfix) with ESMTP id 0955880C9DD7; Thu, 5 Oct 2023 09:42:49 -0700 (PDT) X-Virus-Status: Clean X-Virus-Scanned: clamav-milter 0.103.10 at howler.vger.email Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S234385AbjJEQlt (ORCPT + 99 others); Thu, 5 Oct 2023 12:41:49 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:46986 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S232593AbjJEQkC (ORCPT ); Thu, 5 Oct 2023 12:40:02 -0400 Received: from mail-ej1-x62a.google.com (mail-ej1-x62a.google.com [IPv6:2a00:1450:4864:20::62a]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 7997E4201; Thu, 5 Oct 2023 09:34:28 -0700 (PDT) Received: by mail-ej1-x62a.google.com with SMTP id a640c23a62f3a-99c1c66876aso229592366b.2; Thu, 05 Oct 2023 09:34:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1696523665; x=1697128465; darn=vger.kernel.org; h=content-disposition:mime-version:message-id:subject:cc:to:from:date :from:to:cc:subject:date:message-id:reply-to; bh=TVELeAMbqDGQTgb0H+LdBlcaOEIyA8bnbU3CE39csMo=; b=hGMInpkH4KxvKoa7iTpyK7JnvV16t0CDDH7aqJuatJ5cLWrj20DXUnabz7W6JI63Jl eIdwJ+tF+IJ2G5EMHK3eCVoE5ra+4wzxdmvSogf1Tocwd8WlFPG6ScIeHe7KpQ4skOi7 ZGSxaahuHOxpdgqzbUWlwnOdtn3T+Z7+ijdQYA6ZdakHSr+Iw3/GZ0EiNTlnXRzKjq5s gCmXNqQK7/hBonvTOfvRqqKrKTFL48/a7r8G00T1MvkiBsbIBsiySxSMwd+W6UVNAyaF wvjhH5LlaZ5qUcFu2lwXgzjg8GxG+gONvGnii1fJ2aZ0T7SO1ufe9rGywKx02k5RocZ6 fEig== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1696523665; x=1697128465; h=content-disposition:mime-version:message-id:subject:cc:to:from:date :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=TVELeAMbqDGQTgb0H+LdBlcaOEIyA8bnbU3CE39csMo=; b=ZGQQqxalqSeXPtzitibNKxxBomXTrXjjTgVQjNiWglOGQrK8B5nV+dqKg3Ck3iHS+I XzRroHQmUzdSDP7j0jwTtgt+83OLVTBR97qPA7dgXNMbSIelIi/lXIy3PYgBEqg8xa7s RKqgVjw426RuF4pKn5bAP1vBGR+ZX/yJ7SFQJK+hQl8ZLV4o5z8aN+wKh9Hx8DkcZEva mscrdq7pimOIy7ElpM4zIikV2IbLmcpjbZ0P84+DwbMr0u3JUF7OhHc7h9Iup3orqHwh GyC7KwOVOxzlbUZY8mnpdd9q9q0fV66Zocn37MF3u9gMNPqTV0uXky69liZuYosrD7gx RJSw== X-Gm-Message-State: AOJu0YyZIXRiSaxDpfplhXzXys0P2ubtynSkOBWbSpneeBBV82i4A1dQ IotRGVa47IbUKv6kaB67hA== X-Received: by 2002:a17:907:2704:b0:9ae:5492:64e with SMTP id w4-20020a170907270400b009ae5492064emr4686541ejk.25.1696523664571; Thu, 05 Oct 2023 09:34:24 -0700 (PDT) Received: from p183 ([46.53.253.206]) by smtp.gmail.com with ESMTPSA id m14-20020a1709066d0e00b00991d54db2acsm1428974ejr.44.2023.10.05.09.34.23 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 05 Oct 2023 09:34:23 -0700 (PDT) Date: Thu, 5 Oct 2023 19:34:21 +0300 From: Alexey Dobriyan To: Greg Kroah-Hartman , Jiri Slaby Cc: linux-serial@vger.kernel.org, linux-kernel@vger.kernel.org Subject: stack leak via uart_get_info() ? Message-ID: <967b9ef1-fb36-48bf-9e6a-1b99af24c052@p183> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline X-Spam-Status: No, score=-2.1 required=5.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,FREEMAIL_FROM, RCVD_IN_DNSWL_BLOCKED,SPF_HELO_NONE,SPF_PASS autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org X-Greylist: Sender passed SPF test, not delayed by milter-greylist-4.6.4 (howler.vger.email [0.0.0.0]); Thu, 05 Oct 2023 09:42:49 -0700 (PDT) If this check ever triggers static int uart_get_info(struct tty_port *port, struct serial_struct *retinfo) { uport = uart_port_check(state); if (!uport) goto out; then all those sysfs users will print stack contents to userspace. Can it trigger while sysfs read is executing? Signed-off-by: Alexey Dobriyan --- --- a/drivers/tty/serial/serial_core.c +++ b/drivers/tty/serial/serial_core.c @@ -775,6 +775,8 @@ static int uart_get_info(struct tty_port *port, struct serial_struct *retinfo) struct uart_port *uport; int ret = -ENODEV; + *retinfo = (struct serial_struct){}; + /* * Ensure the state we copy is consistent and no hardware changes * occur as we go