We used to allocate and fetch bit arrays using a sanitized length, but then iterate over them with "j < arg[0]" condition, where arg[0] is not sanitized. This segfaults if arg[0] is huge or negative. This change fixes this. Add test/select.c to capture the case. Signed-off-by: Dr. David Alan Gilbert <dave@treblig.org> Signed-off-by: Denys Vlasenko <dvlasenk@redhat.com>
15 lines
132 B
Plaintext
15 lines
132 B
Plaintext
vfork
|
|
fork
|
|
sig
|
|
skodic
|
|
clone
|
|
leaderkill
|
|
childthread
|
|
sigkill_rain
|
|
wait_must_be_interruptible
|
|
threaded_execve
|
|
mtd
|
|
ubi
|
|
select
|
|
sigreturn
|