lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <yq1k03ir2hl.fsf@ca-mkp.ca.oracle.com> Date: Fri, 25 Nov 2022 19:19:58 -0500 From: "Martin K. Petersen" <martin.petersen@...cle.com> To: Harshit Mogalapalli <harshit.m.mogalapalli@...cle.com> Cc: error27@...il.com, harshit.m.mogalapalli@...il.com, "James E.J. Bottomley" <jejb@...ux.ibm.com>, "Martin K. Petersen" <martin.petersen@...cle.com>, Hannes Reinecke <hare@...e.de>, Douglas Gilbert <dgilbert@...erlog.com>, linux-scsi@...r.kernel.org, linux-kernel@...r.kernel.org Subject: Re: [PATCH] scsi: scsi_debug: Fix a warning in resp_verify() Harshit, > As 'vnum' is controlled by user, so if user tries to allocate memory > larger than(>=) MAX_ORDER, then kcalloc() will fail, it creates a stack > trace and messes up dmesg with a warning. Applied to 6.2/scsi-staging, thanks! -- Martin K. Petersen Oracle Linux Engineering
Powered by blists - more mailing lists