Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1504398

[PATCH 3.10 09/16] crypto: nx - off by one bug in nx_of_update_msc()

From Willy Tarreau <w@1wt.eu>
Newsgroups linux.kernel
Subject [PATCH 3.10 09/16] crypto: nx - off by one bug in nx_of_update_msc()
Date 2016-10-20 01:00 +0200
Message-ID <su807-7Cg-67@gated-at.bofh.it> (permalink)
References <su801-7Cg-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


From: Dan Carpenter <dan.carpenter@oracle.com>

commit e514cc0a492a3f39ef71b31590a7ef67537ee04b upstream.

The props->ap[] array is defined like this:

	struct alg_props ap[NX_MAX_FC][NX_MAX_MODE][3];

So we can see that if msc->fc and msc->mode are == to NX_MAX_FC or
NX_MAX_MODE then we're off by one.

Fixes: ae0222b7289d ('powerpc/crypto: nx driver code supporting nx encryption')
Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Willy Tarreau <w@1wt.eu>
---
 drivers/crypto/nx/nx.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/crypto/nx/nx.c b/drivers/crypto/nx/nx.c
index bbdab6e..fe68964 100644
--- a/drivers/crypto/nx/nx.c
+++ b/drivers/crypto/nx/nx.c
@@ -309,7 +309,7 @@ static void nx_of_update_msc(struct device   *dev,
 		     ((bytes_so_far + sizeof(struct msc_triplet)) <= lenp) &&
 		     i < msc->triplets;
 		     i++) {
-			if (msc->fc > NX_MAX_FC || msc->mode > NX_MAX_MODE) {
+			if (msc->fc >= NX_MAX_FC || msc->mode >= NX_MAX_MODE) {
 				dev_err(dev, "unknown function code/mode "
 					"combo: %d/%d (ignored)\n", msc->fc,
 					msc->mode);
-- 
2.8.0.rc2.1.gbe9624a

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH 3.10 00/16] 3.10.104-stable review Willy Tarreau <w@1wt.eu> - 2016-10-20 01:00 +0200
  [PATCH 3.10 15/16] xen-netback: ref count shared rings Willy Tarreau <w@1wt.eu> - 2016-10-20 01:00 +0200
  [PATCH 3.10 02/16] PCI: Support PCIe devices with short cfg_size Willy Tarreau <w@1wt.eu> - 2016-10-20 01:00 +0200
  [PATCH 3.10 06/16] PCI: Limit config space size for Netronome NFP4000 Willy Tarreau <w@1wt.eu> - 2016-10-20 01:00 +0200
  [PATCH 3.10 05/16] PCI: Add Netronome NFP4000 PF device ID Willy Tarreau <w@1wt.eu> - 2016-10-20 01:00 +0200
  [PATCH 3.10 08/16] megaraid_sas: Fix probing cards without io port Willy Tarreau <w@1wt.eu> - 2016-10-20 01:00 +0200
  [PATCH 3.10 10/16] staging: comedi: daqboard2000: bug fix board type matching code Willy Tarreau <w@1wt.eu> - 2016-10-20 01:00 +0200
  [PATCH 3.10 04/16] PCI: Limit config space size for Netronome NFP6000 family Willy Tarreau <w@1wt.eu> - 2016-10-20 01:00 +0200
  [PATCH 3.10 09/16] crypto: nx - off by one bug in nx_of_update_msc() Willy Tarreau <w@1wt.eu> - 2016-10-20 01:00 +0200
  [PATCH 3.10 12/16] mm: thp: fix SMP race condition between THP page fault and MADV_DONTNEED Willy Tarreau <w@1wt.eu> - 2016-10-20 01:00 +0200

csiph-web