Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1527997
| From | Jiri Slaby <jslaby@suse.cz> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | [patch added to 3.12-stable] tty: limit terminal size to 4M chars |
| Date | 2016-11-22 23:50 +0100 |
| Message-ID | <sGs2Z-4VW-7@gated-at.bofh.it> (permalink) |
| References | <sGs2Z-4VW-9@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
From: Dmitry Vyukov <dvyukov@google.com> This patch has been added to the 3.12 stable tree. If you have any objections, please let us know. =============== commit 32b2921e6a7461fe63b71217067a6cf4bddb132f upstream. Size of kmalloc() in vc_do_resize() is controlled by user. Too large kmalloc() size triggers WARNING message on console. Put a reasonable upper bound on terminal size to prevent WARNINGs. Signed-off-by: Dmitry Vyukov <dvyukov@google.com> CC: David Rientjes <rientjes@google.com> Cc: One Thousand Gnomes <gnomes@lxorguk.ukuu.org.uk> Cc: Greg Kroah-Hartman <gregkh@linuxfoundation.org> Cc: Jiri Slaby <jslaby@suse.com> Cc: Peter Hurley <peter@hurleysoftware.com> Cc: linux-kernel@vger.kernel.org Cc: syzkaller@googlegroups.com Signed-off-by: Jiri Slaby <jslaby@suse.cz> --- drivers/tty/vt/vt.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/drivers/tty/vt/vt.c b/drivers/tty/vt/vt.c index d52e653076f4..60ce423c6364 100644 --- a/drivers/tty/vt/vt.c +++ b/drivers/tty/vt/vt.c @@ -863,6 +863,8 @@ static int vc_do_resize(struct tty_struct *tty, struct vc_data *vc, if (new_cols == vc->vc_cols && new_rows == vc->vc_rows) return 0; + if (new_screen_size > (4 << 20)) + return -EINVAL; newscreen = kmalloc(new_screen_size, GFP_USER); if (!newscreen) return -ENOMEM; -- 2.10.2
Back to linux.kernel | Previous | Next | Find similar | Unroll thread
[patch added to 3.12-stable] tty: limit terminal size to 4M chars Jiri Slaby <jslaby@suse.cz> - 2016-11-22 23:50 +0100
csiph-web