lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Date: Sat, 01 Nov 2014 22:28:03 +0000 From: Ben Hutchings <ben@...adent.org.uk> To: linux-kernel@...r.kernel.org, stable@...r.kernel.org CC: akpm@...ux-foundation.org, "Eliad Peller" <eliad@...ery.com>, "Johannes Berg" <johannes.berg@...el.com>, "Eliad Peller" <eliadx.peller@...el.com> Subject: [PATCH 3.2 001/102] regulatory: add NUL to alpha2 3.2.64-rc1 review patch. If anyone has any objections, please let me know. ------------------ From: Eliad Peller <eliad@...ery.com> commit a5fe8e7695dc3f547e955ad2b662e3e72969e506 upstream. alpha2 is defined as 2-chars array, but is used in multiple places as string (e.g. with nla_put_string calls), which might leak kernel data. Solve it by simply adding an extra char for the NULL terminator, making such operations safe. Signed-off-by: Eliad Peller <eliadx.peller@...el.com> Signed-off-by: Johannes Berg <johannes.berg@...el.com> [bwh: Backported to 3.2: adjust context] Signed-off-by: Ben Hutchings <ben@...adent.org.uk> --- include/net/regulatory.h | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) --- a/include/net/regulatory.h +++ b/include/net/regulatory.h @@ -92,7 +92,7 @@ struct ieee80211_reg_rule { struct ieee80211_regdomain { u32 n_reg_rules; - char alpha2[2]; + char alpha2[3]; struct ieee80211_reg_rule reg_rules[]; }; -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@...r.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
Powered by blists - more mailing lists