char: pcmcia: error out if 'num_bytes_read' is greater than 4 in set_protocol()
authorYu Kuai <yukuai3@huawei.com>
Fri, 21 May 2021 12:06:17 +0000 (20:06 +0800)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Thu, 27 May 2021 12:45:54 +0000 (14:45 +0200)
Theoretically, it will cause index out of bounds error if
'num_bytes_read' is greater than 4. As we expect it(and was tested)
never to be greater than 4, error out if it happens.

Fixes: c1986ee9bea3 ("[PATCH] New Omnikey Cardman 4000 driver")
Signed-off-by: Yu Kuai <yukuai3@huawei.com>
Link: https://lore.kernel.org/r/20210521120617.138396-1-yukuai3@huawei.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
drivers/char/pcmcia/cm4000_cs.c

index 9ec2573..8f1bce0 100644 (file)
@@ -544,6 +544,10 @@ static int set_protocol(struct cm4000_dev *dev, struct ptsreq *ptsreq)
                io_read_num_rec_bytes(iobase, &num_bytes_read);
                if (num_bytes_read >= 4) {
                        DEBUGP(2, dev, "NumRecBytes = %i\n", num_bytes_read);
+                       if (num_bytes_read > 4) {
+                               rc = -EIO;
+                               goto exit_setprotocol;
+                       }
                        break;
                }
                usleep_range(10000, 11000);