lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Date: Sun, 20 Jan 2013 17:31:35 +0800 From: Chen Gang <gang.chen@...anux.com> To: sgruszka@...hat.com, linville@...driver.com CC: linux-wireless@...r.kernel.org, netdev <netdev@...r.kernel.org> Subject: Re: [PATCH] drivers/net/wireless/iwlegacy: use strlcpy instead of strncpy Hello all: sorry, after checking the details: I think this patch is incorrect. we can not assume that the parameter "char *buf" is terminated by '\0' so we should only use strlcpy instead of strncpy, without touching 'min(...' since it is already integrated into main branch (at least, in next-20130118). I should send additional patch to fix it. please help to check, thanks. gchen. 于 2013年01月07日 12:42, Chen Gang 写道: > > The fields must be null-terminated, or simple_strtoul will cause issue. > > Signed-off-by: Chen Gang <gang.chen@...anux.com> > --- > drivers/net/wireless/iwlegacy/3945-mac.c | 2 +- > 1 file changed, 1 insertion(+), 1 deletion(-) > > diff --git a/drivers/net/wireless/iwlegacy/3945-mac.c b/drivers/net/wireless/iwlegacy/3945-mac.c > index d604b40..3726cd6 100644 > --- a/drivers/net/wireless/iwlegacy/3945-mac.c > +++ b/drivers/net/wireless/iwlegacy/3945-mac.c > @@ -3273,7 +3273,7 @@ il3945_store_measurement(struct device *d, struct device_attribute *attr, > > if (count) { > char *p = buffer; > - strncpy(buffer, buf, min(sizeof(buffer), count)); > + strlcpy(buffer, buf, sizeof(buffer)); > channel = simple_strtoul(p, NULL, 0); > if (channel) > params.channel = channel; > -- Chen Gang Asianux Corporation -- To unsubscribe from this list: send the line "unsubscribe netdev" in the body of a message to majordomo@...r.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html
Powered by blists - more mailing lists