Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1393802 > unrolled thread
| Started by | Kangjie Lu <kangjielu@gmail.com> |
|---|---|
| First post | 2016-05-03 22:50 +0200 |
| Last post | 2016-05-03 22:50 +0200 |
| Articles | 1 — 1 participant |
Back to article view | Back to linux.kernel
[PATCH] infoleak fix2 in timer Kangjie Lu <kangjielu@gmail.com> - 2016-05-03 22:50 +0200
| From | Kangjie Lu <kangjielu@gmail.com> |
|---|---|
| Date | 2016-05-03 22:50 +0200 |
| Subject | [PATCH] infoleak fix2 in timer |
| Message-ID | <ruPqy-6Hu-3@gated-at.bofh.it> |
The stack object “r1” has a total size of 32 bytes. Its field “event” and “val” both contain 4 bytes padding. These 8 bytes padding bytes are sent to user without being initialized. Signed-off-by: Kangjie Lu <kjlu@gatech.edu> --- sound/core/timer.c | 1 + 1 file changed, 1 insertion(+) diff --git a/sound/core/timer.c b/sound/core/timer.c index 964f5eb..e98fa5f 100644 --- a/sound/core/timer.c +++ b/sound/core/timer.c @@ -1225,6 +1225,7 @@ static void snd_timer_user_ccallback(struct snd_timer_instance *timeri, tu->tstamp = *tstamp; if ((tu->filter & (1 << event)) == 0 || !tu->tread) return; + memset(&r1, 0, sizeof(r1)); r1.event = event; r1.tstamp = *tstamp; r1.val = resolution; -- 1.9.1
Back to top | Article view | linux.kernel
csiph-web