aboutsummaryrefslogtreecommitdiffstats
path: root/drivers/usb/class
diff options
context:
space:
mode:
authorSven Schnelle <svens@stackframe.org>2012-08-17 21:43:43 +0200
committerBen Hutchings <ben@decadent.org.uk>2012-09-12 03:37:13 +0100
commit76e0246b1c62a12db0c9af652be580019ee4666a (patch)
tree644f0df4d7a7fa06973daae684ff216dfa2bc1ac /drivers/usb/class
parent0a97b367d2da87668e8b20f1d10d6956ed76bb1a (diff)
downloadkernel_samsung_smdk4412-76e0246b1c62a12db0c9af652be580019ee4666a.zip
kernel_samsung_smdk4412-76e0246b1c62a12db0c9af652be580019ee4666a.tar.gz
kernel_samsung_smdk4412-76e0246b1c62a12db0c9af652be580019ee4666a.tar.bz2
USB: CDC ACM: Fix NULL pointer dereference
commit 99f347caa4568cb803862730b3b1f1942639523f upstream. If a device specifies zero endpoints in its interface descriptor, the kernel oopses in acm_probe(). Even though that's clearly an invalid descriptor, we should test wether we have all endpoints. This is especially bad as this oops can be triggered by just plugging a USB device in. Signed-off-by: Sven Schnelle <svens@stackframe.org> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
Diffstat (limited to 'drivers/usb/class')
-rw-r--r--drivers/usb/class/cdc-acm.c3
1 files changed, 2 insertions, 1 deletions
diff --git a/drivers/usb/class/cdc-acm.c b/drivers/usb/class/cdc-acm.c
index 1094469..dbf7d20 100644
--- a/drivers/usb/class/cdc-acm.c
+++ b/drivers/usb/class/cdc-acm.c
@@ -1043,7 +1043,8 @@ skip_normal_probe:
}
- if (data_interface->cur_altsetting->desc.bNumEndpoints < 2)
+ if (data_interface->cur_altsetting->desc.bNumEndpoints < 2 ||
+ control_interface->cur_altsetting->desc.bNumEndpoints == 0)
return -EINVAL;
epctrl = &control_interface->cur_altsetting->endpoint[0].desc;