mirror of
https://github.com/torvalds/linux.git
synced 2026-09-19 00:58:02 +02:00
qeth_snmp_command() and qeth_l3_arp_query() allocate a buffer sized by
a user-supplied length (udata_len) without checking a lower bound, then
set udata_offset to a fixed non-zero value and pass both to a reply
callback. The callback bounds-checks the copy with
if ((udata_len - udata_offset) < len)
Both fields are u32, so a udata_len smaller than udata_offset makes the
subtraction wrap and the check pass, and the following memcpy() writes
past the allocation. A udata_len of 0 also yields ZERO_SIZE_PTR from
kzalloc(), which the existing NULL check does not catch.
Reject buffers smaller than udata_offset before allocating, so the
callback subtraction can no longer underflow.
Fixes:
|
||
|---|---|---|
| .. | ||
| ctcm_dbug.c | ||
| ctcm_dbug.h | ||
| ctcm_fsms.c | ||
| ctcm_fsms.h | ||
| ctcm_main.c | ||
| ctcm_main.h | ||
| ctcm_mpc.c | ||
| ctcm_mpc.h | ||
| ctcm_sysfs.c | ||
| fsm.c | ||
| fsm.h | ||
| ism_drv.c | ||
| ism.h | ||
| Kconfig | ||
| Makefile | ||
| qeth_core_main.c | ||
| qeth_core_mpc.c | ||
| qeth_core_mpc.h | ||
| qeth_core_sys.c | ||
| qeth_core.h | ||
| qeth_ethtool.c | ||
| qeth_l2_main.c | ||
| qeth_l2_sys.c | ||
| qeth_l2.h | ||
| qeth_l3_main.c | ||
| qeth_l3_sys.c | ||
| qeth_l3.h | ||
| smsgiucv_app.c | ||
| smsgiucv.c | ||
| smsgiucv.h | ||