Last active
June 13, 2020 10:37
-
-
Save mansr/91b4da22db112bfba4a2cf3fd8b62950 to your computer and use it in GitHub Desktop.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
From 879a2c0f7a3775a98fcdb7cc8ed973ae8d4d7ea7 Mon Sep 17 00:00:00 2001 | |
From: Mans Rullgard <mans@mansr.com> | |
Date: Thu, 11 Jun 2020 21:40:06 +0100 | |
Subject: [PATCH] i2c: core: check returned size of emulated smbus block read | |
If the i2c bus driver ignores the I2C_M_RECV_LEN flag (as some of | |
them do), it is possible for an I2C_SMBUS_BLOCK_DATA read issued | |
on some random device to return an arbitrary value in the first | |
byte (and nothing else). When this happens, i2c_smbus_xfer_emulated() | |
will happily write past the end of the supplied data buffer, thus | |
causing Bad Things to happen. To prevent this, check the size | |
before copying the data block and return an error if it is too large. | |
Fixes: 209d27c3b167 ("i2c: Emulate SMBus block read over I2C") | |
Signed-off-by: Mans Rullgard <mans@mansr.com> | |
--- | |
drivers/i2c/i2c-core-smbus.c | 7 +++++++ | |
1 file changed, 7 insertions(+) | |
diff --git a/drivers/i2c/i2c-core-smbus.c b/drivers/i2c/i2c-core-smbus.c | |
index 3ac426a8ab5a..a719c26b98ac 100644 | |
--- a/drivers/i2c/i2c-core-smbus.c | |
+++ b/drivers/i2c/i2c-core-smbus.c | |
@@ -495,6 +495,13 @@ static s32 i2c_smbus_xfer_emulated(struct i2c_adapter *adapter, u16 addr, | |
break; | |
case I2C_SMBUS_BLOCK_DATA: | |
case I2C_SMBUS_BLOCK_PROC_CALL: | |
+ if (msg[1].buf[0] > I2C_SMBUS_BLOCK_MAX) { | |
+ dev_err(&adapter->dev, | |
+ "Invalid block size returned: %d\n", | |
+ msg[1].buf[0]); | |
+ status = -EINVAL; | |
+ goto cleanup; | |
+ } | |
for (i = 0; i < msg[1].buf[0] + 1; i++) | |
data->block[i] = msg[1].buf[i]; | |
break; | |
-- | |
2.27.0 | |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
#include <stdio.h> | |
#include <stdlib.h> | |
#include <unistd.h> | |
#include <fcntl.h> | |
#include <sys/ioctl.h> | |
#include <linux/i2c.h> | |
#include <linux/i2c-dev.h> | |
int main(int argc, char **argv) | |
{ | |
struct i2c_smbus_ioctl_data smb = {}; | |
union i2c_smbus_data data = {}; | |
unsigned long addr; | |
int err; | |
int fd; | |
if (argc < 3) { | |
fprintf(stderr, "usage: %s /dev/i2c-N ADDR [DATA-ADDR]\n", | |
argv[0]); | |
return 1; | |
} | |
addr = strtoul(argv[2], NULL, 0); | |
fd = open(argv[1], O_RDWR); | |
if (fd < 0) { | |
perror(argv[1]); | |
return 1; | |
} | |
smb.read_write = I2C_SMBUS_READ; | |
smb.command = argc > 3 ? strtoul(argv[3], NULL, 0) : 0; | |
smb.size = I2C_SMBUS_BLOCK_DATA; | |
smb.data = &data; | |
err = ioctl(fd, I2C_SLAVE_FORCE, addr); | |
if (err) { | |
perror("ioctl: I2C_SLAVE_FORCE"); | |
return 1; | |
} | |
err = ioctl(fd, I2C_SMBUS, &smb); | |
if (err) { | |
perror("ioctl: I2C_SMBUS"); | |
return 1; | |
} | |
printf("%d bytes read, allegedly\n", data.block[0]); | |
close(fd); | |
return 0; | |
} |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment