From: Dan Carpenter Date: Tue, 24 Sep 2013 22:27:44 +0000 (-0700) Subject: cpqarray: fix info leak in ida_locked_ioctl() X-Git-Tag: v4.14-rc1~8874^2~3 X-Git-Url: http://review.tizen.org/git/?a=commitdiff_plain;h=627aad1c01da6f881e7f98d71fd928ca0c316b1a;p=platform%2Fkernel%2Flinux-rpi.git cpqarray: fix info leak in ida_locked_ioctl() The pciinfo struct has a two byte hole after ->dev_fn so stack information could be leaked to the user. This was assigned CVE-2013-2147. Signed-off-by: Dan Carpenter Acked-by: Mike Miller Signed-off-by: Andrew Morton Signed-off-by: Linus Torvalds --- diff --git a/drivers/block/cpqarray.c b/drivers/block/cpqarray.c index 639d26b90b91..2b9440384536 100644 --- a/drivers/block/cpqarray.c +++ b/drivers/block/cpqarray.c @@ -1193,6 +1193,7 @@ out_passthru: ida_pci_info_struct pciinfo; if (!arg) return -EINVAL; + memset(&pciinfo, 0, sizeof(pciinfo)); pciinfo.bus = host->pci_dev->bus->number; pciinfo.dev_fn = host->pci_dev->devfn; pciinfo.board_id = host->board_id;