[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <CAJkuJRh4r9bqjfTAdkFgAQ1Az+zt6HuG85d-fWVQXdgmQDW8dQ@mail.gmail.com>
Date: Mon, 10 Apr 2023 11:17:01 +0900
From: sangsup lee <k1rh4.lee@...il.com>
To: Salvatore Bonaccorso <carnil@...ian.org>
Cc: Xu Yilun <yilun.xu@...el.com>, Wu Hao <hao.wu@...el.com>,
Tom Rix <trix@...hat.com>, Moritz Fischer <mdf@...nel.org>,
linux-fpga@...r.kernel.org, linux-kernel@...r.kernel.org
Subject: Re: [PATCH] fpga: dfl-afu-region: Add overflow checks for region size
and offset
Hi,
In my opinion the code has an insecure code pattern.
The size may have integer overflow condition i think.
But, I did not do dynamic analysis but I did static audit fpga code(I
don't have an fpga device).
because of this. I don't make sure about Yilun's comment.
I think the code must have defensive coding rules.
best regards.
Powered by blists - more mailing lists