summaryrefslogtreecommitdiff
path: root/include/linux/ipack.h
diff options
context:
space:
mode:
authorJiri Slaby <jslaby@suse.cz>2022-07-07 10:25:58 +0200
committerAlexander Grund <flamefire89@gmail.com>2023-11-09 19:17:23 +0100
commitd5eebb7d01fa02ce53ff5d8be50dfafecb9c22f4 (patch)
tree078739306121c5c91cc9df61308c58dc35087739 /include/linux/ipack.h
parentf714603039fbd41f14b37149ee50ced36666ed94 (diff)
tty: use new tty_insert_flip_string_and_push_buffer() in pty_write()
commit a501ab75e7624d133a5a3c7ec010687c8b961d23 upstream. There is a race in pty_write(). pty_write() can be called in parallel with e.g. ioctl(TIOCSTI) or ioctl(TCXONC) which also inserts chars to the buffer. Provided, tty_flip_buffer_push() in pty_write() is called outside the lock, it can commit inconsistent tail. This can lead to out of bounds writes and other issues. See the Link below. To fix this, we have to introduce a new helper called tty_insert_flip_string_and_push_buffer(). It does both tty_insert_flip_string() and tty_flip_buffer_commit() under the port lock. It also calls queue_work(), but outside the lock. See 71a174b39f10 (pty: do tty_flip_buffer_push without port->lock in pty_write) for the reasons. Keep the helper internal-only (in drivers' tty.h). It is not intended to be used widely. Link: https://seclists.org/oss-sec/2022/q2/155 Fixes: 71a174b39f10 (pty: do tty_flip_buffer_push without port->lock in pty_write) Change-Id: I1f08439cc9047ee56df0681c3dfc5cd18f4b5a37
Diffstat (limited to 'include/linux/ipack.h')
0 files changed, 0 insertions, 0 deletions