You've already forked linux-apfs
mirror of
https://github.com/linux-apfs/linux-apfs.git
synced 2026-05-01 15:00:59 -07:00
arch: sparc: kernel: check the memory length before use strcpy().
For the related next strcpy(), the destination length is less than 512,
but the source maximize length may be 'OPROMMAXPARAM' (4096) which is
more than 512.
One work flow may:
openprom_sunos_ioctl() -> if (cmd == OPROMSETOPT)
getstrings() -> will alloc buffer with size 'OPROMMAXPARAM'.
opromsetopt() -> devide the buffer into 'var' and 'value'
of_set_property() -> pass
prom_setprop() -> pass
ldom_set_var()
And do not mind the additional 4 alignment buffer increasing, since
'sizeof(pkt) - sizeof(pkt.header)' is 4 alignment at least.
Signed-off-by: Chen Gang <gang.chen@asianux.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
This commit is contained in:
committed by
David S. Miller
parent
bfffbea1aa
commit
f118e9abdd
@@ -783,6 +783,16 @@ void ldom_set_var(const char *var, const char *value)
|
||||
char *base, *p;
|
||||
int msg_len, loops;
|
||||
|
||||
if (strlen(var) + strlen(value) + 2 >
|
||||
sizeof(pkt) - sizeof(pkt.header)) {
|
||||
printk(KERN_ERR PFX
|
||||
"contents length: %zu, which more than max: %lu,"
|
||||
"so could not set (%s) variable to (%s).\n",
|
||||
strlen(var) + strlen(value) + 2,
|
||||
sizeof(pkt) - sizeof(pkt.header), var, value);
|
||||
return;
|
||||
}
|
||||
|
||||
memset(&pkt, 0, sizeof(pkt));
|
||||
pkt.header.data.tag.type = DS_DATA;
|
||||
pkt.header.data.handle = cp->handle;
|
||||
|
||||
Reference in New Issue
Block a user