Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1489266 > unrolled thread

[PATCH][V2] cxgb4: fix signed wrap around when decrementing index idx

Started byColin King <colin.king@canonical.com>
First post2016-09-22 20:20 +0200
Last post2016-09-23 13:30 +0200
Articles 2 — 2 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH][V2] cxgb4: fix signed wrap around when decrementing index idx Colin King <colin.king@canonical.com> - 2016-09-22 20:20 +0200
    Re: [PATCH][V2] cxgb4: fix signed wrap around when decrementing  index idx David Miller <davem@davemloft.net> - 2016-09-23 13:30 +0200

#1489266 — [PATCH][V2] cxgb4: fix signed wrap around when decrementing index idx

FromColin King <colin.king@canonical.com>
Date2016-09-22 20:20 +0200
Subject[PATCH][V2] cxgb4: fix signed wrap around when decrementing index idx
Message-ID<skgLf-1mw-19@gated-at.bofh.it>
From: Colin Ian King <colin.king@canonical.com>

Change predecrement compare to post decrement compare to avoid an
unsigned integer wrap-around comparison when decrementing idx in
the while loop.

For example, when idx is zero, the current situation will
predecrement idx in the while loop, wrapping idx to the maximum
signed integer and cause out of bounds reads on rxq_info->msix_tbl[idx].

Signed-off-by: Colin Ian King <colin.king@canonical.com>
---
 drivers/net/ethernet/chelsio/cxgb4/cxgb4_uld.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/net/ethernet/chelsio/cxgb4/cxgb4_uld.c b/drivers/net/ethernet/chelsio/cxgb4/cxgb4_uld.c
index d12a73e..42a9c8d 100644
--- a/drivers/net/ethernet/chelsio/cxgb4/cxgb4_uld.c
+++ b/drivers/net/ethernet/chelsio/cxgb4/cxgb4_uld.c
@@ -367,7 +367,7 @@ int request_msix_queue_irqs_uld(struct adapter *adap, unsigned int uld_type)
 	}
 	return 0;
 unwind:
-	while (--idx >= 0) {
+	while (idx-- > 0) {
 		bmap_idx = rxq_info->msix_tbl[idx];
 		free_msix_idx_in_bmap(adap, bmap_idx);
 		free_irq(adap->msix_info_ulds[bmap_idx].vec,
-- 
2.9.3

[toc] | [next] | [standalone]


#1489955 — Re: [PATCH][V2] cxgb4: fix signed wrap around when decrementing index idx

FromDavid Miller <davem@davemloft.net>
Date2016-09-23 13:30 +0200
SubjectRe: [PATCH][V2] cxgb4: fix signed wrap around when decrementing index idx
Message-ID<skwQ2-2Yn-23@gated-at.bofh.it>
In reply to#1489266
From: Colin King <colin.king@canonical.com>
Date: Thu, 22 Sep 2016 18:48:58 +0100

> From: Colin Ian King <colin.king@canonical.com>
> 
> Change predecrement compare to post decrement compare to avoid an
> unsigned integer wrap-around comparison when decrementing idx in
> the while loop.
> 
> For example, when idx is zero, the current situation will
> predecrement idx in the while loop, wrapping idx to the maximum
> signed integer and cause out of bounds reads on rxq_info->msix_tbl[idx].
> 
> Signed-off-by: Colin Ian King <colin.king@canonical.com>

Applied to net-next, thanks.

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web