sxgbe: Fix off by one in samsung driver strncpy size arg
[ Upstream commit f3cc008bf6
]
This patch fixes an off-by-one error in strncpy size argument in
drivers/net/ethernet/samsung/sxgbe/sxgbe_main.c. The issue is that in:
strncmp(opt, "eee_timer:", 6)
the passed string literal: "eee_timer:" has 10 bytes (without the NULL
byte) and the passed size argument is 6. As a result, the logic will
also accept other, malformed strings, e.g. "eee_tiXXX:".
This bug doesn't seem to have any security impact since its present in
module's cmdline parsing code.
Signed-off-by: Dominik Czarnota <dominik.b.czarnota@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
This commit is contained in:
committed by
Greg Kroah-Hartman
parent
753ea21f2a
commit
24e72d55bc
@ -2279,7 +2279,7 @@ static int __init sxgbe_cmdline_opt(char *str)
|
|||||||
if (!str || !*str)
|
if (!str || !*str)
|
||||||
return -EINVAL;
|
return -EINVAL;
|
||||||
while ((opt = strsep(&str, ",")) != NULL) {
|
while ((opt = strsep(&str, ",")) != NULL) {
|
||||||
if (!strncmp(opt, "eee_timer:", 6)) {
|
if (!strncmp(opt, "eee_timer:", 10)) {
|
||||||
if (kstrtoint(opt + 10, 0, &eee_timer))
|
if (kstrtoint(opt + 10, 0, &eee_timer))
|
||||||
goto err;
|
goto err;
|
||||||
}
|
}
|
||||||
|
Reference in New Issue
Block a user