summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorJustin M. Forbes <jforbes@fedoraproject.org>2018-01-29 08:50:45 -0600
committerJustin M. Forbes <jforbes@fedoraproject.org>2018-01-29 08:50:45 -0600
commit4ad5c1a63e413c86e6da581d03eae5e2432a7582 (patch)
treeb08591ab55ea2e58afb4da13b9beb5888664b91d
parentd1d4d6ac4f9d6b61a237d03e7f58a35732428579 (diff)
downloadkernel-4ad5c1a63e413c86e6da581d03eae5e2432a7582.tar.gz
kernel-4ad5c1a63e413c86e6da581d03eae5e2432a7582.tar.xz
kernel-4ad5c1a63e413c86e6da581d03eae5e2432a7582.zip
Fix CVE-2018-5750 (rhbz 1539706 1539708)
-rw-r--r--ACPI-sbshc-remove-raw-pointer-from-printk-message.patch41
-rw-r--r--kernel.spec6
2 files changed, 47 insertions, 0 deletions
diff --git a/ACPI-sbshc-remove-raw-pointer-from-printk-message.patch b/ACPI-sbshc-remove-raw-pointer-from-printk-message.patch
new file mode 100644
index 000000000..0aa10d0af
--- /dev/null
+++ b/ACPI-sbshc-remove-raw-pointer-from-printk-message.patch
@@ -0,0 +1,41 @@
+From patchwork Fri Jan 19 09:06:03 2018
+Content-Type: text/plain; charset="utf-8"
+MIME-Version: 1.0
+Content-Transfer-Encoding: 7bit
+Subject: ACPI: sbshc: remove raw pointer from printk message
+From: "gregkh@linuxfoundation.org" <gregkh@linuxfoundation.org>
+X-Patchwork-Id: 10174835
+Message-Id: <20180119090603.GA7775@kroah.com>
+To: "Rafael J. Wysocki" <rjw@rjwysocki.net>, Len Brown <lenb@kernel.org>
+Cc: linux-acpi@vger.kernel.org, linux-kernel@vger.kernel.org,
+ Wang Qize <wang_qize@venustech.com.cn>
+Date: Fri, 19 Jan 2018 10:06:03 +0100
+
+There's no need to be printing a raw kernel pointer to the kernel log at
+every boot. So just remove it, and change the whole message to use the
+correct dev_info() call at the same time.
+
+Reported-by: Wang Qize <wang_qize@venustech.com.cn>
+Cc: stable <stable@vger.kernel.org>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+Acked-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
+---
+To unsubscribe from this list: send the line "unsubscribe linux-acpi" in
+the body of a message to majordomo@vger.kernel.org
+More majordomo info at http://vger.kernel.org/majordomo-info.html
+
+diff --git a/drivers/acpi/sbshc.c b/drivers/acpi/sbshc.c
+index 2fa8304171e0..217e1caf58d6 100644
+--- a/drivers/acpi/sbshc.c
++++ b/drivers/acpi/sbshc.c
+@@ -275,8 +275,8 @@ static int acpi_smbus_hc_add(struct acpi_device *device)
+ device->driver_data = hc;
+
+ acpi_ec_add_query_handler(hc->ec, hc->query_bit, NULL, smbus_alarm, hc);
+- printk(KERN_INFO PREFIX "SBS HC: EC = 0x%p, offset = 0x%0x, query_bit = 0x%0x\n",
+- hc->ec, hc->offset, hc->query_bit);
++ dev_info(&device->dev, "SBS HC: offset = 0x%0x, query_bit = 0x%0x\n",
++ hc->offset, hc->query_bit);
+
+ return 0;
+ }
diff --git a/kernel.spec b/kernel.spec
index 068c9b085..6fbc7c521 100644
--- a/kernel.spec
+++ b/kernel.spec
@@ -644,6 +644,9 @@ Patch642: prevent-bounds-check-bypass-via-speculative-execution.patch
# Fix crash on Xwayland using nouveau
Patch650: dma-buf-fix-reservation_object_wait_timeout_rcu-once-more-v2.patch
+# CVE-2018-5750 rhbz 1539706 1539708
+Patch651: ACPI-sbshc-remove-raw-pointer-from-printk-message.patch
+
# END OF PATCH DEFINITIONS
%endif
@@ -1902,6 +1905,9 @@ fi
#
#
%changelog
+* Mon Jan 29 2018 Justin M. Forbes <jforbes@fedoraproject.org>
+- Fix CVE-2018-5750 (rhbz 1539706 1539708)
+
* Mon Jan 29 2018 Laura Abbott <labbott@redhat.com> - 4.15.0-1
- Linux v4.15
- Disable debugging options.