Johan Hovold 8c76d7cd52 USB: serial: safe_serial: fix information leak in completion handler
Add missing sanity check to the bulk-in completion handler to avoid an
integer underflow that could be triggered by a malicious device.

This avoids leaking up to 56 bytes from after the URB transfer buffer to
user space.

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Cc: stable <stable@vger.kernel.org>
Signed-off-by: Johan Hovold <johan@kernel.org>
2017-03-08 16:14:42 +01:00
..
2017-02-22 11:15:59 -08:00
2015-12-18 09:30:34 -08:00
2017-01-26 09:49:13 +01:00
2016-05-20 21:12:25 -07:00
2017-01-26 09:49:13 +01:00
2017-02-09 13:57:05 +01:00
2017-01-26 09:49:13 +01:00