Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1698471
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | Re: [PATCH v3/resubmit 1/3] staging: gs_fpgaboot: add buffer overflow checks |
| Date | 2017-07-28 07:00 +0200 |
| Message-ID | <u85xv-7vg-9@gated-at.bofh.it> (permalink) |
| References | <u7FD3-7Vk-3@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On Wed, Jul 26, 2017 at 09:13:57PM -0400, Jacob von Chorus wrote: > Four fields in struct fpgaimage are char arrays of length MAX_STR (256). > The amount of data read into these buffers is controlled by a length > field in the bitstream file read from userspace. If a corrupt or > malicious firmware file was supplied, kernel data beyond these buffers > can be overwritten arbitrarily. > > This patch adds a check of the bitstream's length value to ensure it > fits within the bounds of the allocated buffers. An error condition is > returned from gs_read_bitstream if any of the reads fail. > > Signed-off-by: Jacob von Chorus <jacobvonchorus@cwphoto.ca> > > v3: > - use >= to prevent an integer overflow in the comparison > - use get_unaligned_be functions to interpret length fields > - fix remainder of file to use valid error codes > > v2: > - char arrays converted to u8 arrays > - replace error return value with proper error code in > gs_read_bitstream > --- All of the v2: and such needs to go below the --- line, as Documentation/SubmittingPatches says to do. Please fix that up and resend the series. thanks, greg k-h
Back to linux.kernel | Previous | Next — Previous in thread | Find similar | Unroll thread
[PATCH v3/resubmit 1/3] staging: gs_fpgaboot: add buffer overflow checks Jacob von Chorus <jacobvonchorus@cwphoto.ca> - 2017-07-27 03:20 +0200 [PATCH v3/resubmit 3/3] staging: gs_fpgaboot: return valid error codes Jacob von Chorus <jacobvonchorus@cwphoto.ca> - 2017-07-27 03:20 +0200 [PATCH v3/resubmit 2/3] staging: gs_fpgaboot: change char to u8 Jacob von Chorus <jacobvonchorus@cwphoto.ca> - 2017-07-27 03:20 +0200 Re: [PATCH v3/resubmit 1/3] staging: gs_fpgaboot: add buffer overflow checks Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-07-28 07:00 +0200
csiph-web