* [PATCH] ipc: fix compat msgrcv with negative msgtyp
@ 2014-01-15 13:52 Mateusz Guzik
2015-03-09 10:43 ` Fwd: " Masanari Iida
0 siblings, 1 reply; 2+ messages in thread
From: Mateusz Guzik @ 2014-01-15 13:52 UTC (permalink / raw)
To: linux-kernel; +Cc: Gabriellla Schmidt, Al Viro
Compat function takes msgtyp argument as u32 and passes it down to
do_msgrcv which results in casting to long, thus the sign is lost
and we get a big positive number instead.
Cast the argument to signed type before passing it down.
Signed-off-by: Mateusz Guzik <mguzik@redhat.com>
Reported-by: Gabriellla Schmidt <gsc@bruker.de>
Cc: Al Viro <viro@zeniv.linux.org.uk>
---
ipc/compat.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/ipc/compat.c b/ipc/compat.c
index 892f658..d3b3760 100644
--- a/ipc/compat.c
+++ b/ipc/compat.c
@@ -381,7 +381,7 @@ COMPAT_SYSCALL_DEFINE6(ipc, u32, call, int, first, int, second,
uptr = compat_ptr(ipck.msgp);
fifth = ipck.msgtyp;
}
- return do_msgrcv(first, uptr, second, fifth, third,
+ return do_msgrcv(first, uptr, second, (s32)fifth, third,
compat_do_msg_fill);
}
case MSGGET:
--
1.8.3.1
^ permalink raw reply [flat|nested] 2+ messages in thread
* Fwd: [PATCH] ipc: fix compat msgrcv with negative msgtyp
2014-01-15 13:52 [PATCH] ipc: fix compat msgrcv with negative msgtyp Mateusz Guzik
@ 2015-03-09 10:43 ` Masanari Iida
0 siblings, 0 replies; 2+ messages in thread
From: Masanari Iida @ 2015-03-09 10:43 UTC (permalink / raw)
To: stable, linux-kernel, regkh, Andrew Morton; +Cc: mguzik
Greg,
Somebody asking to backport following patch into 3.10.x stable tree.
https://lkml.org/lkml/2015/3/7/316
The patch is identified as following commit ID in Linus's tree.
commit e7ca2552369c1dfe0216c626baf82c3d83ec36bb
Author: Mateusz Guzik <mguzik@redhat.com>
Date: Mon Jan 27 17:07:11 2014 -0800
ipc: fix compat msgrcv with negative msgtyp
For your convinience, the patch is included in this e-mail.
Masanari Iida
---------- Forwarded message ----------
From: Mateusz Guzik <mguzik@redhat.com>
Date: Wed, Jan 15, 2014 at 10:52 PM
Subject: [PATCH] ipc: fix compat msgrcv with negative msgtyp
To: linux-kernel@vger.kernel.org
Cc: Gabriellla Schmidt <gsc@bruker.de>, Al Viro <viro@zeniv.linux.org.uk>
Compat function takes msgtyp argument as u32 and passes it down to
do_msgrcv which results in casting to long, thus the sign is lost
and we get a big positive number instead.
Cast the argument to signed type before passing it down.
Signed-off-by: Mateusz Guzik <mguzik@redhat.com>
Reported-by: Gabriellla Schmidt <gsc@bruker.de>
Cc: Al Viro <viro@zeniv.linux.org.uk>
---
ipc/compat.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/ipc/compat.c b/ipc/compat.c
index 892f658..d3b3760 100644
--- a/ipc/compat.c
+++ b/ipc/compat.c
@@ -381,7 +381,7 @@ COMPAT_SYSCALL_DEFINE6(ipc, u32, call, int, first,
int, second,
uptr = compat_ptr(ipck.msgp);
fifth = ipck.msgtyp;
}
- return do_msgrcv(first, uptr, second, fifth, third,
+ return do_msgrcv(first, uptr, second, (s32)fifth, third,
compat_do_msg_fill);
}
case MSGGET:
--
1.8.3.1
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2015-03-09 10:44 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2014-01-15 13:52 [PATCH] ipc: fix compat msgrcv with negative msgtyp Mateusz Guzik
2015-03-09 10:43 ` Fwd: " Masanari Iida
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®