Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1594427 > unrolled thread

[PATCH RESEND v1] qed: Fix copy of uninitialized memory

Started byRobert Foss <robert.foss@collabora.com>
First post2017-03-07 17:50 +0100
Last post2017-03-09 22:20 +0100
Articles 2 — 2 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH RESEND v1] qed: Fix copy of uninitialized memory Robert Foss <robert.foss@collabora.com> - 2017-03-07 17:50 +0100
    Re: [PATCH RESEND v1] qed: Fix copy of uninitialized memory David Miller <davem@davemloft.net> - 2017-03-09 22:20 +0100

#1594427 — [PATCH RESEND v1] qed: Fix copy of uninitialized memory

FromRobert Foss <robert.foss@collabora.com>
Date2017-03-07 17:50 +0100
Subject[PATCH RESEND v1] qed: Fix copy of uninitialized memory
Message-ID<tiqtd-1LM-43@gated-at.bofh.it>
In qed_ll2_start_ooo() the ll2_info variable is uninitialized and then
passed to qed_ll2_acquire_connection() where it is copied into a new
memory space.

This shouldn't cause any issue as long as non of the copied memory is
every read.
But the potential for a bug being introduced by reading this memory
is real.

Detected by CoverityScan, CID#1399632 ("Uninitialized scalar variable")

Signed-off-by: Robert Foss <robert.foss@collabora.com>
---
 drivers/net/ethernet/qlogic/qed/qed_ll2.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/net/ethernet/qlogic/qed/qed_ll2.c b/drivers/net/ethernet/qlogic/qed/qed_ll2.c
index 9a0b9af10a57..5fb34db377c8 100644
--- a/drivers/net/ethernet/qlogic/qed/qed_ll2.c
+++ b/drivers/net/ethernet/qlogic/qed/qed_ll2.c
@@ -968,7 +968,7 @@ static int qed_ll2_start_ooo(struct qed_dev *cdev,
 {
 	struct qed_hwfn *hwfn = QED_LEADING_HWFN(cdev);
 	u8 *handle = &hwfn->pf_params.iscsi_pf_params.ll2_ooo_queue_id;
-	struct qed_ll2_conn ll2_info;
+	struct qed_ll2_conn ll2_info = { 0 };
 	int rc;
 
 	ll2_info.conn_type = QED_LL2_TYPE_ISCSI_OOO;
-- 
2.11.0.453.g787f75f05

[toc] | [next] | [standalone]


#1596390

FromDavid Miller <davem@davemloft.net>
Date2017-03-09 22:20 +0100
Message-ID<tjdDz-2iO-1@gated-at.bofh.it>
In reply to#1594427
From: Robert Foss <robert.foss@collabora.com>
Date: Tue,  7 Mar 2017 11:46:25 -0500

> In qed_ll2_start_ooo() the ll2_info variable is uninitialized and then
> passed to qed_ll2_acquire_connection() where it is copied into a new
> memory space.
> 
> This shouldn't cause any issue as long as non of the copied memory is
> every read.
> But the potential for a bug being introduced by reading this memory
> is real.
> 
> Detected by CoverityScan, CID#1399632 ("Uninitialized scalar variable")
> 
> Signed-off-by: Robert Foss <robert.foss@collabora.com>

Applied.

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web