From 45bdbf9c9f6957f2421d9c21cb5ac900b32620f5 Mon Sep 17 00:00:00 2001 From: Linus Torvalds Date: Mon, 12 Dec 2022 18:05:47 -0300 Subject: [PATCH] proc: avoid integer type confusion in get_proc_long proc_get_long() is passed a size_t, but then assigns it to an 'int' variable for the length. Let's not do that, even if our IO paths are limited to MAX_RW_COUNT (exactly because of these kinds of type errors). So do the proper test in the rigth type. Reported-by: Kyle Zeng Signed-off-by: Linus Torvalds (cherry picked from commit e6cfaf34be9fcd1a8285a294e18986bfc41a409c) CVE-2022-4378 Signed-off-by: Thadeu Lima de Souza Cascardo Signed-off-by: Timo Aaltonen --- kernel/sysctl.c | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/kernel/sysctl.c b/kernel/sysctl.c index b24a7f16e54d8..39476c5eff8c4 100644 --- a/kernel/sysctl.c +++ b/kernel/sysctl.c @@ -462,13 +462,12 @@ static int proc_get_long(char **buf, size_t *size, unsigned long *val, bool *neg, const char *perm_tr, unsigned perm_tr_len, char *tr) { - int len; char *p, tmp[TMPBUFLEN]; + ssize_t len = *size; - if (!*size) + if (len <= 0) return -EINVAL; - len = *size; if (len > TMPBUFLEN - 1) len = TMPBUFLEN - 1;