031-04-MIPS-BCM47XX-Use-strnchr-to-avoid-reading-out-of-the.patch 1.3 KB

12345678910111213141516171819202122232425262728293031323334353637383940
  1. From 80aaaa8b93d860f828e2cf883f307894640765f0 Mon Sep 17 00:00:00 2001
  2. From: =?UTF-8?q?Rafa=C5=82=20Mi=C5=82ecki?= <zajec5@gmail.com>
  3. Date: Wed, 10 Dec 2014 11:49:54 +0100
  4. Subject: [PATCH] MIPS: BCM47XX: Use strnchr to avoid reading out of the buffer
  5. MIME-Version: 1.0
  6. Content-Type: text/plain; charset=UTF-8
  7. Content-Transfer-Encoding: 8bit
  8. Signed-off-by: Rafał Miłecki <zajec5@gmail.com>
  9. Cc: Hauke Mehrtens <hauke@hauke-m.de>
  10. Cc: Paul Walmsley <paul@pwsan.com>
  11. Cc: linux-mips@linux-mips.org
  12. Patchwork: https://patchwork.linux-mips.org/patch/8662/
  13. Signed-off-by: Ralf Baechle <ralf@linux-mips.org>
  14. ---
  15. arch/mips/bcm47xx/nvram.c | 6 ++++--
  16. 1 file changed, 4 insertions(+), 2 deletions(-)
  17. --- a/arch/mips/bcm47xx/nvram.c
  18. +++ b/arch/mips/bcm47xx/nvram.c
  19. @@ -175,7 +175,7 @@ static int nvram_init(void)
  20. int bcm47xx_nvram_getenv(const char *name, char *val, size_t val_len)
  21. {
  22. char *var, *value, *end, *eq;
  23. - int err;
  24. + int data_left, err;
  25. if (!name)
  26. return -EINVAL;
  27. @@ -191,7 +191,9 @@ int bcm47xx_nvram_getenv(const char *nam
  28. end = nvram_buf + sizeof(nvram_buf) - 2;
  29. end[0] = end[1] = '\0';
  30. for (; *var; var = value + strlen(value) + 1) {
  31. - eq = strchr(var, '=');
  32. + data_left = end - var;
  33. +
  34. + eq = strnchr(var, data_left, '=');
  35. if (!eq)
  36. break;
  37. value = eq + 1;