Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1222144 > unrolled thread

[PATCH 1/2] staging: dgap: fix possible NULL dereference

Started bySudip Mukherjee <sudipm.mukherjee@gmail.com>
First post2015-09-10 14:00 +0200
Last post2015-09-12 06:40 +0200
Articles 2 — 2 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH 1/2] staging: dgap: fix possible NULL dereference Sudip Mukherjee <sudipm.mukherjee@gmail.com> - 2015-09-10 14:00 +0200
    Re: [PATCH 1/2] staging: dgap: fix possible NULL dereference Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2015-09-12 06:40 +0200

#1222144 — [PATCH 1/2] staging: dgap: fix possible NULL dereference

FromSudip Mukherjee <sudipm.mukherjee@gmail.com>
Date2015-09-10 14:00 +0200
Subject[PATCH 1/2] staging: dgap: fix possible NULL dereference
Message-ID<q78Ge-vY-7@gated-at.bofh.it>
The return pointer from dgap_getword() is used in strcmp() where it is
dereferenced. But dgap_getword() can return NULL.
Lets put a check there and return 0 as error.

Signed-off-by: Sudip Mukherjee <sudip@vectorindia.org>
---
 drivers/staging/dgap/dgap.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/drivers/staging/dgap/dgap.c b/drivers/staging/dgap/dgap.c
index 9112dd2..20ba258 100644
--- a/drivers/staging/dgap/dgap.c
+++ b/drivers/staging/dgap/dgap.c
@@ -349,6 +349,8 @@ static int dgap_gettok(char **in)
 
 	if (strstr(dgap_cword, "board")) {
 		w = dgap_getword(in);
+		if (!w)
+			return 0;
 		snprintf(dgap_cword, MAXCWORD, "%s", w);
 		for (t = dgap_brdtype; t->token != 0; t++) {
 			if (!strcmp(w, t->string))
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [next] | [standalone]


#1223308

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2015-09-12 06:40 +0200
Message-ID<q7KLw-6L3-25@gated-at.bofh.it>
In reply to#1222144
On Thu, Sep 10, 2015 at 05:24:58PM +0530, Sudip Mukherjee wrote:
> The return pointer from dgap_getword() is used in strcmp() where it is
> dereferenced. But dgap_getword() can return NULL.
> Lets put a check there and return 0 as error.
> 
> Signed-off-by: Sudip Mukherjee <sudip@vectorindia.org>
> ---
>  drivers/staging/dgap/dgap.c | 2 ++
>  1 file changed, 2 insertions(+)

While this change is all nice and fine, this driver is totally abusing
the firmware kernel interface to read in a "configuration file" and then
parse it within the driver.  That's not ok at all, no tty driver should
ever need this.  Please work to just rip all of that crap out.

thanks,

greg k-h
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web