forked from mirrors/linux
		
	waitid(): Add missing access_ok() checks
Adds missing access_ok() checks.
CVE-2017-5123
Reported-by: Chris Salls <chrissalls5@gmail.com>
Signed-off-by: Kees Cook <keescook@chromium.org>
Acked-by: Al Viro <viro@zeniv.linux.org.uk>
Fixes: 4c48abe91b ("waitid(): switch copyout of siginfo to unsafe_put_user()")
Cc: stable@kernel.org # 4.13
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
			
			
This commit is contained in:
		
							parent
							
								
									ff33952e4d
								
							
						
					
					
						commit
						96ca579a1e
					
				
					 1 changed files with 6 additions and 0 deletions
				
			
		|  | @ -1610,6 +1610,9 @@ SYSCALL_DEFINE5(waitid, int, which, pid_t, upid, struct siginfo __user *, | |||
| 	if (!infop) | ||||
| 		return err; | ||||
| 
 | ||||
| 	if (!access_ok(VERIFY_WRITE, infop, sizeof(*infop))) | ||||
| 		goto Efault; | ||||
| 
 | ||||
| 	user_access_begin(); | ||||
| 	unsafe_put_user(signo, &infop->si_signo, Efault); | ||||
| 	unsafe_put_user(0, &infop->si_errno, Efault); | ||||
|  | @ -1735,6 +1738,9 @@ COMPAT_SYSCALL_DEFINE5(waitid, | |||
| 	if (!infop) | ||||
| 		return err; | ||||
| 
 | ||||
| 	if (!access_ok(VERIFY_WRITE, infop, sizeof(*infop))) | ||||
| 		goto Efault; | ||||
| 
 | ||||
| 	user_access_begin(); | ||||
| 	unsafe_put_user(signo, &infop->si_signo, Efault); | ||||
| 	unsafe_put_user(0, &infop->si_errno, Efault); | ||||
|  |  | |||
		Loading…
	
		Reference in a new issue
	
	 Kees Cook
						Kees Cook