linux-uconsole/drivers/usb
Ingo Rohloff cba6467277 usb: usbfs: Suppress problematic bind and unbind uevents.
[ Upstream commit abb0b3d96a ]

commit 1455cf8dbf ("driver core: emit uevents when device is bound
to a driver") added bind and unbind uevents when a driver is bound or
unbound to a physical device.

For USB devices which are handled via the generic usbfs layer (via
libusb for example), this is problematic:
Each time a user space program calls
   ioctl(usb_fd, USBDEVFS_CLAIMINTERFACE, &usb_intf_nr);
and then later
   ioctl(usb_fd, USBDEVFS_RELEASEINTERFACE, &usb_intf_nr);
The kernel will now produce a bind or unbind event, which does not
really contain any useful information.

This allows a user space program to run a DoS attack against programs
which listen to uevents (in particular systemd/eudev/upowerd):
A malicious user space program just has to call in a tight loop

   ioctl(usb_fd, USBDEVFS_CLAIMINTERFACE, &usb_intf_nr);
   ioctl(usb_fd, USBDEVFS_RELEASEINTERFACE, &usb_intf_nr);

With this loop the malicious user space program floods the kernel and
all programs listening to uevents with tons of bind and unbind
events.

This patch suppresses uevents for ioctls USBDEVFS_CLAIMINTERFACE and
USBDEVFS_RELEASEINTERFACE.

Signed-off-by: Ingo Rohloff <ingo.rohloff@lauterbach.com>
Link: https://lore.kernel.org/r/20191011115518.2801-1-ingo.rohloff@lauterbach.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2019-12-31 16:35:16 +01:00
..
atm USB: atm: ueagle-atm: add missing endpoint check 2019-12-17 20:34:37 +01:00
c67x00
chipidea usb: chipidea: Fix otg event handler 2019-11-20 18:47:07 +01:00
class usb: usbtmc: uninitialized symbol 'actual' in usbtmc_ioctl_clear 2019-11-20 18:47:53 +01:00
common usb: common: Consider only available nodes for dr_mode 2019-04-03 06:26:27 +02:00
core usb: usbfs: Suppress problematic bind and unbind uevents. 2019-12-31 16:35:16 +01:00
dwc2 usb: dwc2: use a longer core rest timeout in dwc2_core_reset() 2019-12-05 09:21:25 +01:00
dwc3 usb: dwc3: ep0: Clear started flag on completion 2019-12-17 20:34:45 +01:00
early
gadget usb: gadget: pch_udc: fix use after free 2019-12-17 20:34:28 +01:00
host xhci: fix USB3 device initiated resume race with roothub autosuspend 2019-12-21 10:57:44 +01:00
image USB: microtek: fix info-leak at probe 2019-10-17 13:45:05 -07:00
isp1760 usb: isp1760: remove redundant variable 'selector' 2018-07-13 15:41:56 +02:00
misc USB: adutux: fix interface sanity check 2019-12-17 20:34:40 +01:00
mon usb: mon: Fix a deadlock in usbmon between mmap and read 2019-12-17 20:34:41 +01:00
mtu3 usb: mtu3: fix dbginfo in qmu_tx_zlp_error_handler 2019-12-13 08:52:32 +01:00
musb soc: sunxi: Fix missing dependency on REGMAP_MMIO 2019-05-10 17:54:10 +02:00
phy usb: phy: fix link errors 2019-03-13 14:02:34 -07:00
renesas_usbhs usb: renesas_usbhs: add suspend event support in gadget mode 2019-12-31 16:34:54 +01:00
roles usb: roles: fix a potential use after free 2019-12-17 20:34:39 +01:00
serial USB: serial: io_edgeport: fix epic endpoint lookup 2019-12-17 20:34:38 +01:00
storage USB: uas: heed CAPACITY_HEURISTICS 2019-12-17 20:34:30 +01:00
typec usb: typec: fix use after free in typec_register_port() 2019-12-17 20:35:27 +01:00
usbip usbip: Fix uninitialized symbol 'nents' in stub_recv_cmd_submit() 2019-12-01 09:17:41 +01:00
wusbcore usb: wusbcore: security: cast sizeof to int for comparison 2018-07-02 18:08:19 +02:00
Kconfig usb: roles: Add a description for the class to Kconfig 2019-01-09 17:38:40 +01:00
Makefile
README
usb-skeleton.c USB: usb-skeleton: fix NULL-deref on disconnect 2019-10-17 13:44:50 -07:00

To understand all the Linux-USB framework, you'll use these resources:

    * This source code.  This is necessarily an evolving work, and
      includes kerneldoc that should help you get a current overview.
      ("make pdfdocs", and then look at "usb.pdf" for host side and
      "gadget.pdf" for peripheral side.)  Also, Documentation/usb has
      more information.

    * The USB 2.0 specification (from www.usb.org), with supplements
      such as those for USB OTG and the various device classes.
      The USB specification has a good overview chapter, and USB
      peripherals conform to the widely known "Chapter 9".

    * Chip specifications for USB controllers.  Examples include
      host controllers (on PCs, servers, and more); peripheral
      controllers (in devices with Linux firmware, like printers or
      cell phones); and hard-wired peripherals like Ethernet adapters.

    * Specifications for other protocols implemented by USB peripheral
      functions.  Some are vendor-specific; others are vendor-neutral
      but just standardized outside of the www.usb.org team.

Here is a list of what each subdirectory here is, and what is contained in
them.

core/		- This is for the core USB host code, including the
		  usbfs files and the hub class driver ("hub_wq").

host/		- This is for USB host controller drivers.  This
		  includes UHCI, OHCI, EHCI, and others that might
		  be used with more specialized "embedded" systems.

gadget/		- This is for USB peripheral controller drivers and
		  the various gadget drivers which talk to them.


Individual USB driver directories.  A new driver should be added to the
first subdirectory in the list below that it fits into.

image/		- This is for still image drivers, like scanners or
		  digital cameras.
../input/	- This is for any driver that uses the input subsystem,
		  like keyboard, mice, touchscreens, tablets, etc.
../media/	- This is for multimedia drivers, like video cameras,
		  radios, and any other drivers that talk to the v4l
		  subsystem.
../net/		- This is for network drivers.
serial/		- This is for USB to serial drivers.
storage/	- This is for USB mass-storage drivers.
class/		- This is for all USB device drivers that do not fit
		  into any of the above categories, and work for a range
		  of USB Class specified devices. 
misc/		- This is for all USB device drivers that do not fit
		  into any of the above categories.