]> git.itanic.dy.fi Git - linux-stable/commit
ubifs: wbuf: Don't leak kernel memory to flash
authorRichard Weinberger <richard@nod.at>
Mon, 16 Nov 2020 21:05:30 +0000 (22:05 +0100)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Wed, 30 Dec 2020 10:26:13 +0000 (11:26 +0100)
commit1343995da97ef18c818537676392bf619b88c284
treebb20cfdd1c0ce4ff223683b309809202f876d01f
parent9ee56388802a703fd93ef6aaa4547a5407048a4e
ubifs: wbuf: Don't leak kernel memory to flash

commit 20f1431160c6b590cdc269a846fc5a448abf5b98 upstream.

Write buffers use a kmalloc()'ed buffer, they can leak
up to seven bytes of kernel memory to flash if writes are not
aligned.
So use ubifs_pad() to fill these gaps with padding bytes.
This was never a problem while scanning because the scanner logic
manually aligns node lengths and skips over these gaps.

Cc: <stable@vger.kernel.org>
Fixes: 1e51764a3c2ac05a2 ("UBIFS: add new flash file system")
Signed-off-by: Richard Weinberger <richard@nod.at>
Reviewed-by: Zhihao Cheng <chengzhihao1@huawei.com>
Signed-off-by: Richard Weinberger <richard@nod.at>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
fs/ubifs/io.c