Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1232973 > unrolled thread

[PATCH 2/4] lib/vsprintf.c: also improve sanity check in bstr_printf()

Started byRasmus Villemoes <linux@rasmusvillemoes.dk>
First post2015-09-25 19:50 +0200
Last post2015-09-29 00:40 +0200
Articles 2 — 2 participants

Back to article view | Back to linux.kernel

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  [PATCH 2/4] lib/vsprintf.c: also improve sanity check in bstr_printf() Rasmus Villemoes <linux@rasmusvillemoes.dk> - 2015-09-25 19:50 +0200
    Re: [PATCH 2/4] lib/vsprintf.c: also improve sanity check in bstr_printf() Kees Cook <keescook@chromium.org> - 2015-09-29 00:40 +0200

#1232973 — [PATCH 2/4] lib/vsprintf.c: also improve sanity check in bstr_printf()

FromRasmus Villemoes <linux@rasmusvillemoes.dk>
Date2015-09-25 19:50 +0200
Subject[PATCH 2/4] lib/vsprintf.c: also improve sanity check in bstr_printf()
Message-ID<qcFia-8p1-13@gated-at.bofh.it>
Quoting from 2aa2f9e21e4e ("lib/vsprintf.c: improve sanity check in
vsnprintf()"):

    On 64 bit, size may very well be huge even if bit 31 happens to be 0.
    Somehow it doesn't feel right that one can pass a 5 GiB buffer but not a
    3 GiB one.  So cap at INT_MAX as was probably the intention all along.
    This is also the made-up value passed by sprintf and vsprintf.

I should have seen this copy-pasted instance back then, but let's just
do it now.

Signed-off-by: Rasmus Villemoes <linux@rasmusvillemoes.dk>
---
 lib/vsprintf.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/lib/vsprintf.c b/lib/vsprintf.c
index f2590a80937f..03fa10b4be96 100644
--- a/lib/vsprintf.c
+++ b/lib/vsprintf.c
@@ -2294,7 +2294,7 @@ int bstr_printf(char *buf, size_t size, const char *fmt, const u32 *bin_buf)
 	char *str, *end;
 	const char *args = (const char *)bin_buf;
 
-	if (WARN_ON_ONCE((int) size < 0))
+	if (WARN_ON_ONCE(size > INT_MAX))
 		return 0;
 
 	str = buf;
-- 
2.1.3

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [next] | [standalone]


#1234553

FromKees Cook <keescook@chromium.org>
Date2015-09-29 00:40 +0200
Message-ID<qdPfr-4Ba-9@gated-at.bofh.it>
In reply to#1232973
On Fri, Sep 25, 2015 at 10:41 AM, Rasmus Villemoes
<linux@rasmusvillemoes.dk> wrote:
> Quoting from 2aa2f9e21e4e ("lib/vsprintf.c: improve sanity check in
> vsnprintf()"):
>
>     On 64 bit, size may very well be huge even if bit 31 happens to be 0.
>     Somehow it doesn't feel right that one can pass a 5 GiB buffer but not a
>     3 GiB one.  So cap at INT_MAX as was probably the intention all along.
>     This is also the made-up value passed by sprintf and vsprintf.
>
> I should have seen this copy-pasted instance back then, but let's just
> do it now.
>
> Signed-off-by: Rasmus Villemoes <linux@rasmusvillemoes.dk>

Acked-by: Kees Cook <keescook@chromium.org>

-Kees

-- 
Kees Cook
Chrome OS Security
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web