From f09bfcd5372a413cd8d67b81de7f70146bb8e131 Mon Sep 17 00:00:00 2001 From: Takashi Iwai Date: May 19 2023 15:20:47 +0000 Subject: media: dvbdev: fix error logic at dvb_register_device() (CVE-2022-45884 bsc#1205756). --- diff --git a/patches.suse/media-dvbdev-fix-error-logic-at-dvb_register_device.patch b/patches.suse/media-dvbdev-fix-error-logic-at-dvb_register_device.patch new file mode 100644 index 0000000..deff76c --- /dev/null +++ b/patches.suse/media-dvbdev-fix-error-logic-at-dvb_register_device.patch @@ -0,0 +1,50 @@ +From 1fec2ecc252301110e4149e6183fa70460d29674 Mon Sep 17 00:00:00 2001 +From: Mauro Carvalho Chehab +Date: Wed, 9 Jun 2021 14:32:29 +0200 +Subject: [PATCH] media: dvbdev: fix error logic at dvb_register_device() +Git-commit: 1fec2ecc252301110e4149e6183fa70460d29674 +Patch-mainline: v5.14-rc1 +References: CVE-2022-45884 bsc#1205756 + +As reported by smatch: + + drivers/media/dvb-core/dvbdev.c: drivers/media/dvb-core/dvbdev.c:510 dvb_register_device() warn: '&dvbdev->list_head' not removed from list + drivers/media/dvb-core/dvbdev.c: drivers/media/dvb-core/dvbdev.c:530 dvb_register_device() warn: '&dvbdev->list_head' not removed from list + drivers/media/dvb-core/dvbdev.c: drivers/media/dvb-core/dvbdev.c:545 dvb_register_device() warn: '&dvbdev->list_head' not removed from list + +The error logic inside dvb_register_device() doesn't remove +devices from the dvb_adapter_list in case of errors. + +Signed-off-by: Mauro Carvalho Chehab +Acked-by: Takashi Iwai + +--- + drivers/media/dvb-core/dvbdev.c | 3 +++ + 1 file changed, 3 insertions(+) + +--- a/drivers/media/dvb-core/dvbdev.c ++++ b/drivers/media/dvb-core/dvbdev.c +@@ -481,6 +481,7 @@ int dvb_register_device(struct dvb_adapt + break; + + if (minor == MAX_DVB_MINORS) { ++ list_del (&dvbdev->list_head); + kfree(dvbdevfops); + kfree(dvbdev); + up_write(&minor_rwsem); +@@ -501,6 +502,7 @@ int dvb_register_device(struct dvb_adapt + __func__); + + dvb_media_device_free(dvbdev); ++ list_del (&dvbdev->list_head); + kfree(dvbdevfops); + kfree(dvbdev); + up_write(&minor_rwsem); +@@ -517,6 +519,7 @@ int dvb_register_device(struct dvb_adapt + pr_err("%s: failed to create device dvb%d.%s%d (%ld)\n", + __func__, adap->num, dnames[type], id, PTR_ERR(clsdev)); + dvb_media_device_free(dvbdev); ++ list_del (&dvbdev->list_head); + kfree(dvbdevfops); + kfree(dvbdev); + return PTR_ERR(clsdev); diff --git a/series.conf b/series.conf index 90297f6..541babe 100644 --- a/series.conf +++ b/series.conf @@ -26608,6 +26608,7 @@ patches.suse/can-bcm-fix-infoleak-in-struct-bcm_msg_head.patch patches.suse/kvm-do-not-allow-mapping-valid-but-non-reference-cou.patch patches.suse/memstick_rtsx_usb_ms_fix_UAF.patch + patches.suse/media-dvbdev-fix-error-logic-at-dvb_register_device.patch patches.suse/Bluetooth-cmtp-fix-file-refcount-when-cmtp_attach_de.patch patches.suse/can-bcm-delay-release-of-struct-bcm_op-after-synchro.patch patches.suse/sctp-validate-from_addr_param-return.patch