Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1335348
| From | Tomi Valkeinen <tomi.valkeinen@ti.com> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | Re: [patch] video: fbdev: metronomefb: two harmless off by one bugs |
| Date | 2016-02-16 14:00 +0100 |
| Message-ID | <r2Nou-7Xf-41@gated-at.bofh.it> (permalink) |
| References | <qWF0B-4FU-1@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
[Multipart message — attachments visible in raw view] - view raw
On 30/01/16 16:44, Dan Carpenter wrote: > par->metromem_cmd->args[] is an array of 31 elements of size u16. Here > we have initialized the first "i" elements and want to set the rest to > zero. > > The issue here is that ARRAY_SIZE(par->metromem_cmd->args) is 31 and not > 32 as in the original code. It means that we set ->csum to zero, but > that is harmless because we immediately set it to the correct value on > the next line. > > Still, the buffer overflow upsets static checkers so let's correct the > math. Thanks, queued for 4.6. Tomi
Back to linux.kernel | Previous | Next | Find similar | Unroll thread
Re: [patch] video: fbdev: metronomefb: two harmless off by one bugs Tomi Valkeinen <tomi.valkeinen@ti.com> - 2016-02-16 14:00 +0100
csiph-web