lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <Y7g7sp6UJJrYKihK@gondor.apana.org.au> Date: Fri, 6 Jan 2023 23:18:10 +0800 From: Herbert Xu <herbert@...dor.apana.org.au> To: Roberto Sassu <roberto.sassu@...weicloud.com> Cc: dhowells@...hat.com, davem@...emloft.net, zohar@...ux.ibm.com, dmitry.kasatkin@...il.com, paul@...l-moore.com, jmorris@...ei.org, serge@...lyn.com, ebiggers@...nel.org, linux-integrity@...r.kernel.org, linux-security-module@...r.kernel.org, keyrings@...r.kernel.org, linux-crypto@...r.kernel.org, linux-kernel@...r.kernel.org, stable@...r.kernel.org Subject: Re: [PATCH v5 1/2] lib/mpi: Fix buffer overrun when SG is too long On Tue, Dec 27, 2022 at 03:27:39PM +0100, Roberto Sassu wrote: > From: Herbert Xu <herbert@...dor.apana.org.au> > > The helper mpi_read_raw_from_sgl sets the number of entries in > the SG list according to nbytes. However, if the last entry > in the SG list contains more data than nbytes, then it may overrun > the buffer because it only allocates enough memory for nbytes. > > Fixes: 2d4d1eea540b ("lib/mpi: Add mpi sgl helpers") > Reported-by: Roberto Sassu <roberto.sassu@...weicloud.com> > Signed-off-by: Herbert Xu <herbert@...dor.apana.org.au> > --- > lib/mpi/mpicoder.c | 3 ++- > 1 file changed, 2 insertions(+), 1 deletion(-) Patch applied. Thanks. -- Email: Herbert Xu <herbert@...dor.apana.org.au> Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt
Powered by blists - more mailing lists