lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening PHC | |
Open Source and information security mailing list archives
| ||
|
Date: Sat, 21 May 2022 08:49:20 +0200 From: Takashi Iwai <tiwai@...e.de> To: Kees Cook <keescook@...omium.org> Cc: Jaroslav Kysela <perex@...ex.cz>, Takashi Iwai <tiwai@...e.com>, alsa-devel@...a-project.org, linux-kernel@...r.kernel.org, linux-hardening@...r.kernel.org Subject: Re: [PATCH] ALSA: lola: Bounds check loop iterator against streams array size On Fri, 20 May 2022 18:55:37 +0200, Kees Cook wrote: > > GCC 12 sees that it's technically possible for num_streams to be larger > than ARRAY_SIZE(pcm->streams). Bounds-check the iterator. > > ../sound/pci/lola/lola_pcm.c: In function 'lola_pcm_update': > ../sound/pci/lola/lola_pcm.c:567:64: warning: array subscript [0, 31] is outside array bounds of 'struct lola_stream[16]' [-Warray-bounds] > 567 | struct lola_stream *str = &pcm->streams[i]; > | ~~~~~~~~~~~~^~~ > In file included from ../sound/pci/lola/lola_pcm.c:15: > ../sound/pci/lola/lola.h:307:28: note: while referencing 'streams' > 307 | struct lola_stream streams[MAX_STREAM_COUNT]; > | ^~~~~~~ > > Cc: Jaroslav Kysela <perex@...ex.cz> > Cc: Takashi Iwai <tiwai@...e.com> > Cc: alsa-devel@...a-project.org > Signed-off-by: Kees Cook <keescook@...omium.org> Thanks, applied now. Takashi
Powered by blists - more mailing lists