Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1335348
| Path | csiph.com!eternal-september.org!feeder.eternal-september.org!aioe.org!bofh.it!news.nic.it!robomod |
|---|---|
| From | Tomi Valkeinen <tomi.valkeinen@ti.com> |
| Newsgroups | linux.kernel |
| Subject | Re: [patch] video: fbdev: metronomefb: two harmless off by one bugs |
| Date | Tue, 16 Feb 2016 14:00:02 +0100 |
| Message-ID | <r2Nou-7Xf-41@gated-at.bofh.it> (permalink) |
| References | <qWF0B-4FU-1@gated-at.bofh.it> |
| X-Original-To | Dan Carpenter <dan.carpenter@oracle.com>, Jean-Christophe Plagniol-Villard <plagnioj@jcrosoft.com>, Jaya Kumar <jayakumar.lkml@gmail.com> |
| User-Agent | Mozilla/5.0 (X11; Linux x86_64; rv:38.0) Gecko/20100101 Thunderbird/38.5.1 |
| MIME-Version | 1.0 |
| Content-Type | multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="PcdhGRTfgmFqTPB1eXbrHsFMTBttBa4Xm" |
| Sender | robomod@news.nic.it |
| List-ID | <linux-kernel.vger.kernel.org> |
| X-Mailing-List | linux-kernel@vger.kernel.org |
| Approved | robomod@news.nic.it |
| Lines | 50 |
| Organization | linux.* mail to news gateway |
| X-Original-Cc | <linux-fbdev@vger.kernel.org>, <linux-kernel@vger.kernel.org>, <kernel-janitors@vger.kernel.org> |
| X-Original-Date | Tue, 16 Feb 2016 14:53:30 +0200 |
| X-Original-Message-ID | <56C31BCA.2020606@ti.com> |
| X-Original-References | <20160130144432.GF3462@mwanda> |
| X-Original-Sender | linux-kernel-owner@vger.kernel.org |
| Xref | csiph.com linux.kernel:1335348 |
Show key headers only | View raw
[Multipart message — attachments visible in raw view] - view raw
On 30/01/16 16:44, Dan Carpenter wrote: > par->metromem_cmd->args[] is an array of 31 elements of size u16. Here > we have initialized the first "i" elements and want to set the rest to > zero. > > The issue here is that ARRAY_SIZE(par->metromem_cmd->args) is 31 and not > 32 as in the original code. It means that we set ->csum to zero, but > that is harmless because we immediately set it to the correct value on > the next line. > > Still, the buffer overflow upsets static checkers so let's correct the > math. Thanks, queued for 4.6. Tomi
Back to linux.kernel | Previous | Next | Find similar | Unroll thread
Re: [patch] video: fbdev: metronomefb: two harmless off by one bugs Tomi Valkeinen <tomi.valkeinen@ti.com> - 2016-02-16 14:00 +0100
csiph-web