mirror of
https://github.com/torvalds/linux.git
synced 2026-09-11 20:13:02 +02:00
tipc: Dont send random pad bytes in RESET/ACTIVATE messages
The interface name is passed in a fixed length (TIPC_MAX_IF_NAME) buffer.
Replace the strcpy(data, l->if_name) with memcpy() so that the
pad bytes are actually written (l->if_name[] is zero padded)
rather than sending random bytes from the skb to the remote system.
Replace two other strcpy() with strscpy().
Fixes: e74a386d70 ("tipc: remove pre-allocated message header in link struct")
Signed-off-by: David Laight <david.laight.linux@gmail.com>
Reviewed-by: Tung Nguyen <tung.quang.nguyen@est.tech>
Link: https://patch.msgid.link/20260829115813.188600-1-david.laight.linux@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
This commit is contained in:
parent
b3b76e9f4f
commit
81c600c263
|
|
@ -504,7 +504,7 @@ bool tipc_link_create(struct net *net, char *if_name, int bearer_id,
|
|||
snprintf(l->name, sizeof(l->name), "%s:%s-%s:unknown",
|
||||
self_str, if_name, peer_str);
|
||||
|
||||
strcpy(l->if_name, if_name);
|
||||
strscpy(l->if_name, if_name);
|
||||
l->addr = peer;
|
||||
l->peer_caps = peer_caps;
|
||||
l->net = net;
|
||||
|
|
@ -574,7 +574,7 @@ bool tipc_link_bc_create(struct net *net, u32 ownnode, u32 peer, u8 *peer_id,
|
|||
snprintf(l->name, sizeof(l->name), "%s:%s", tipc_bclink_name,
|
||||
peer_str);
|
||||
} else {
|
||||
strcpy(l->name, tipc_bclink_name);
|
||||
strscpy(l->name, tipc_bclink_name);
|
||||
}
|
||||
trace_tipc_link_reset(l, TIPC_DUMP_ALL, "bclink created!");
|
||||
tipc_link_reset(l);
|
||||
|
|
@ -1898,7 +1898,7 @@ static void tipc_link_build_proto_msg(struct tipc_link *l, int mtyp, bool probe,
|
|||
msg_set_dest_session(hdr, l->peer_session);
|
||||
}
|
||||
msg_set_max_pkt(hdr, l->advertised_mtu);
|
||||
strcpy(data, l->if_name);
|
||||
memcpy(data, l->if_name, TIPC_MAX_IF_NAME);
|
||||
msg_set_size(hdr, INT_H_SIZE + TIPC_MAX_IF_NAME);
|
||||
skb_trim(skb, INT_H_SIZE + TIPC_MAX_IF_NAME);
|
||||
}
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user