drivers/video/sis/sis_main.c: prevent reading uninitialized stack memory
The FBIOGET_VBLANK device ioctl allows unprivileged users to read 16 bytes of uninitialized stack memory, because the "reserved" member of the fb_vblank struct declared on the stack is not altered or zeroed before being copied back to the user. This patch takes care of it. Signed-off-by: Dan Rosenberg <dan.j.rosenberg@gmail.com> Cc: Thomas Winischhofer <thomas@winischhofer.net> Cc: <stable@kernel.org> Signed-off-by: Andrew Morton <akpm@linux-foundation.org> Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
This commit is contained in:
parent
cb1dcc0ff4
commit
fd02db9de7
1 changed files with 3 additions and 0 deletions
|
@ -1701,6 +1701,9 @@ static int sisfb_ioctl(struct fb_info *info, unsigned int cmd,
|
|||
break;
|
||||
|
||||
case FBIOGET_VBLANK:
|
||||
|
||||
memset(&sisvbblank, 0, sizeof(struct fb_vblank));
|
||||
|
||||
sisvbblank.count = 0;
|
||||
sisvbblank.flags = sisfb_setupvbblankflags(ivideo, &sisvbblank.vcount, &sisvbblank.hcount);
|
||||
|
||||
|
|
Loading…
Reference in a new issue