Files
linux/drivers/usb/serial
Johan Hovold 8c76d7cd52 USB: serial: safe_serial: fix information leak in completion handler
Add missing sanity check to the bulk-in completion handler to avoid an
integer underflow that could be triggered by a malicious device.

This avoids leaking up to 56 bytes from after the URB transfer buffer to
user space.

Fixes: 1da177e4c3 ("Linux-2.6.12-rc2")
Cc: stable <stable@vger.kernel.org>
Signed-off-by: Johan Hovold <johan@kernel.org>
2017-03-08 16:14:42 +01:00
..
2011-03-31 11:26:23 -03:00
2010-05-20 13:21:47 -07:00
2015-12-18 09:30:34 -08:00
2008-02-01 14:34:47 -08:00
2017-01-26 09:49:13 +01:00
2017-01-26 09:49:13 +01:00
2017-01-26 09:49:13 +01:00
2008-07-22 13:03:22 -07:00