Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1489266 > unrolled thread
| Started by | Colin King <colin.king@canonical.com> |
|---|---|
| First post | 2016-09-22 20:20 +0200 |
| Last post | 2016-09-23 13:30 +0200 |
| Articles | 2 — 2 participants |
Back to article view | Back to linux.kernel
[PATCH][V2] cxgb4: fix signed wrap around when decrementing index idx Colin King <colin.king@canonical.com> - 2016-09-22 20:20 +0200
Re: [PATCH][V2] cxgb4: fix signed wrap around when decrementing index idx David Miller <davem@davemloft.net> - 2016-09-23 13:30 +0200
| From | Colin King <colin.king@canonical.com> |
|---|---|
| Date | 2016-09-22 20:20 +0200 |
| Subject | [PATCH][V2] cxgb4: fix signed wrap around when decrementing index idx |
| Message-ID | <skgLf-1mw-19@gated-at.bofh.it> |
From: Colin Ian King <colin.king@canonical.com>
Change predecrement compare to post decrement compare to avoid an
unsigned integer wrap-around comparison when decrementing idx in
the while loop.
For example, when idx is zero, the current situation will
predecrement idx in the while loop, wrapping idx to the maximum
signed integer and cause out of bounds reads on rxq_info->msix_tbl[idx].
Signed-off-by: Colin Ian King <colin.king@canonical.com>
---
drivers/net/ethernet/chelsio/cxgb4/cxgb4_uld.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/chelsio/cxgb4/cxgb4_uld.c b/drivers/net/ethernet/chelsio/cxgb4/cxgb4_uld.c
index d12a73e..42a9c8d 100644
--- a/drivers/net/ethernet/chelsio/cxgb4/cxgb4_uld.c
+++ b/drivers/net/ethernet/chelsio/cxgb4/cxgb4_uld.c
@@ -367,7 +367,7 @@ int request_msix_queue_irqs_uld(struct adapter *adap, unsigned int uld_type)
}
return 0;
unwind:
- while (--idx >= 0) {
+ while (idx-- > 0) {
bmap_idx = rxq_info->msix_tbl[idx];
free_msix_idx_in_bmap(adap, bmap_idx);
free_irq(adap->msix_info_ulds[bmap_idx].vec,
--
2.9.3
[toc] | [next] | [standalone]
| From | David Miller <davem@davemloft.net> |
|---|---|
| Date | 2016-09-23 13:30 +0200 |
| Subject | Re: [PATCH][V2] cxgb4: fix signed wrap around when decrementing index idx |
| Message-ID | <skwQ2-2Yn-23@gated-at.bofh.it> |
| In reply to | #1489266 |
From: Colin King <colin.king@canonical.com> Date: Thu, 22 Sep 2016 18:48:58 +0100 > From: Colin Ian King <colin.king@canonical.com> > > Change predecrement compare to post decrement compare to avoid an > unsigned integer wrap-around comparison when decrementing idx in > the while loop. > > For example, when idx is zero, the current situation will > predecrement idx in the while loop, wrapping idx to the maximum > signed integer and cause out of bounds reads on rxq_info->msix_tbl[idx]. > > Signed-off-by: Colin Ian King <colin.king@canonical.com> Applied to net-next, thanks.
[toc] | [prev] | [standalone]
Back to top | Article view | linux.kernel
csiph-web