Commit eb558037 authored by Linus Torvalds's avatar Linus Torvalds Committed by Chris Wright

[PATCH] Insanity avoidance in /proc (CVE-2005-4605)

Insanity avoidance in /proc

The old /proc interfaces were never updated to use loff_t, and are just
generally broken.  Now, we should be using the seq_file interface for
all of the proc files, but converting the legacy functions is more work
than most people care for and has little upside..

But at least we can make the non-LFS rules explicit, rather than just
insanely wrapping the offset or something.
Signed-off-by: default avatarLinus Torvalds <torvalds@osdl.org>
Signed-off-by: default avatarChris Wright <chrisw@sous-sol.org>
Signed-off-by: default avatarGreg Kroah-Hartman <gregkh@suse.de>
parent 3946ca02
...@@ -54,6 +54,18 @@ proc_file_read(struct file *file, char __user *buf, size_t nbytes, ...@@ -54,6 +54,18 @@ proc_file_read(struct file *file, char __user *buf, size_t nbytes,
ssize_t n, count; ssize_t n, count;
char *start; char *start;
struct proc_dir_entry * dp; struct proc_dir_entry * dp;
unsigned long long pos;
/*
* Gaah, please just use "seq_file" instead. The legacy /proc
* interfaces cut loff_t down to off_t for reads, and ignore
* the offset entirely for writes..
*/
pos = *ppos;
if (pos > MAX_NON_LFS)
return 0;
if (nbytes > MAX_NON_LFS - pos)
nbytes = MAX_NON_LFS - pos;
dp = PDE(inode); dp = PDE(inode);
if (!(page = (char*) __get_free_page(GFP_KERNEL))) if (!(page = (char*) __get_free_page(GFP_KERNEL)))
...@@ -202,30 +214,17 @@ proc_file_write(struct file *file, const char __user *buffer, ...@@ -202,30 +214,17 @@ proc_file_write(struct file *file, const char __user *buffer,
static loff_t static loff_t
proc_file_lseek(struct file *file, loff_t offset, int orig) proc_file_lseek(struct file *file, loff_t offset, int orig)
{ {
lock_kernel(); loff_t retval = -EINVAL;
switch (orig) { switch (orig) {
case 0:
if (offset < 0)
goto out;
file->f_pos = offset;
unlock_kernel();
return(file->f_pos);
case 1: case 1:
if (offset + file->f_pos < 0) offset += file->f_pos;
goto out; /* fallthrough */
file->f_pos += offset; case 0:
unlock_kernel(); if (offset < 0 || offset > MAX_NON_LFS)
return(file->f_pos); break;
case 2: file->f_pos = retval = offset;
goto out;
default:
goto out;
} }
return retval;
out:
unlock_kernel();
return -EINVAL;
} }
static int proc_notify_change(struct dentry *dentry, struct iattr *iattr) static int proc_notify_change(struct dentry *dentry, struct iattr *iattr)
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment