This is a note to let you know that I've just added the patch titled

    USB: ums_realtek: do not use stack memory for DMA in __do_config_autodelink

to the 3.3-stable tree which can be found at:
    
http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary

The filename of the patch is:
     
usb-ums_realtek-do-not-use-stack-memory-for-dma-in-__do_config_autodelink.patch
and it can be found in the queue-3.3 subdirectory.

If you, or anyone else, feels it should not be added to the stable tree,
please let <[email protected]> know about it.


>From 4898e07174b79013afd2b422ef6c4336ef8e6783 Mon Sep 17 00:00:00 2001
From: "[email protected]" <[email protected]>
Date: Mon, 20 Feb 2012 15:34:34 -0500
Subject: USB: ums_realtek: do not use stack memory for DMA in 
__do_config_autodelink

From: Josh Boyer <[email protected]>

commit 4898e07174b79013afd2b422ef6c4336ef8e6783 upstream.

__do_config_autodelink passes the data variable to the transport function.
If the calling functions pass a stack variable, this will eventually trigger
a DMA-API debug backtrace for mapping stack memory in the DMA buffer.  Fix
this by calling kmemdup for the passed data instead.

Signed-off-by: Josh Boyer <[email protected]>
Signed-off-by: Greg Kroah-Hartman <[email protected]>

---
 drivers/usb/storage/realtek_cr.c |    8 +++++++-
 1 file changed, 7 insertions(+), 1 deletion(-)

--- a/drivers/usb/storage/realtek_cr.c
+++ b/drivers/usb/storage/realtek_cr.c
@@ -507,9 +507,14 @@ static int __do_config_autodelink(struct
 {
        int retval;
        u8 cmnd[12] = {0};
+       u8 *buf;
 
        US_DEBUGP("%s, addr = 0xfe47, len = %d\n", __FUNCTION__, len);
 
+       buf = kmemdup(data, len, GFP_NOIO);
+       if (!buf)
+               return USB_STOR_TRANSPORT_ERROR;
+
        cmnd[0] = 0xF0;
        cmnd[1] = 0x0E;
        cmnd[2] = 0xfe;
@@ -517,7 +522,8 @@ static int __do_config_autodelink(struct
        cmnd[4] = (u8)(len >> 8);
        cmnd[5] = (u8)len;
 
-       retval = rts51x_bulk_transport_special(us, 0, cmnd, 12, data, len, 
DMA_TO_DEVICE, NULL);
+       retval = rts51x_bulk_transport_special(us, 0, cmnd, 12, buf, len, 
DMA_TO_DEVICE, NULL);
+       kfree(buf);
        if (retval != USB_STOR_TRANSPORT_GOOD) {
                return -EIO;
        }


Patches currently in stable-queue which might be from [email protected] are

queue-3.3/usb-ums_realtek-do-not-use-stack-memory-for-dma-in-__do_config_autodelink.patch
--
To unsubscribe from this list: send the line "unsubscribe stable" in
the body of a message to [email protected]
More majordomo info at  http://vger.kernel.org/majordomo-info.html

Reply via email to