* [PATCH] proc: fix unterminated string
@ 2012-09-17 10:49 Alan Cox
2012-09-17 13:59 ` Alan Cox
0 siblings, 1 reply; 2+ messages in thread
From: Alan Cox @ 2012-09-17 10:49 UTC (permalink / raw)
To: akpm, linux-kernel
From: Alan Cox <alan@linux.intel.com>
oom_score_adj_write doesn't terminate the string as it should. Also fix
sched_autogroup_write and other copy/pastes of the bug.
Signed-off-by: Alan Cox <alan@linux.intel.com>
Cc: Horses <stable@vger.kernel.org>
---
fs/proc/base.c | 2 ++
fs/proc/task_mmu.c | 1 +
2 files changed, 3 insertions(+)
diff --git a/fs/proc/base.c b/fs/proc/base.c
index 21fb230..4d42cf18 100644
--- a/fs/proc/base.c
+++ b/fs/proc/base.c
@@ -910,6 +910,7 @@ static ssize_t oom_score_adj_write(struct file *file, const char __user *buf,
err = -EFAULT;
goto out;
}
+ buffer[count] = '\0';
err = kstrtoint(strstrip(buffer), 0, &oom_score_adj);
if (err)
@@ -1192,6 +1193,7 @@ sched_autogroup_write(struct file *file, const char __user *buf,
count = sizeof(buffer) - 1;
if (copy_from_user(buffer, buf, count))
return -EFAULT;
+ buffer[count] = '\0';
err = kstrtoint(strstrip(buffer), 0, &nice);
if (err < 0)
diff --git a/fs/proc/task_mmu.c b/fs/proc/task_mmu.c
index 79827ce..a1dae68 100644
--- a/fs/proc/task_mmu.c
+++ b/fs/proc/task_mmu.c
@@ -639,6 +639,7 @@ static ssize_t clear_refs_write(struct file *file, const char __user *buf,
count = sizeof(buffer) - 1;
if (copy_from_user(buffer, buf, count))
return -EFAULT;
+ buffer[count] = '\0';
rv = kstrtoint(strstrip(buffer), 10, &type);
if (rv < 0)
return rv;
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: [PATCH] proc: fix unterminated string
2012-09-17 10:49 [PATCH] proc: fix unterminated string Alan Cox
@ 2012-09-17 13:59 ` Alan Cox
0 siblings, 0 replies; 2+ messages in thread
From: Alan Cox @ 2012-09-17 13:59 UTC (permalink / raw)
To: Alan Cox; +Cc: akpm, linux-kernel
On Mon, 17 Sep 2012 11:49:30 +0100
Alan Cox <alan@lxorguk.ukuu.org.uk> wrote:
> From: Alan Cox <alan@linux.intel.com>
>
> oom_score_adj_write doesn't terminate the string as it should. Also fix
> sched_autogroup_write and other copy/pastes of the bug.
>
> Signed-off-by: Alan Cox <alan@linux.intel.com>
> Cc: Horses <stable@vger.kernel.org>
Ok ignore this one - its in fact safe having poked at it further - the
memset ensures the buffer is terminated. Ugly but the existing code works
fine 8)
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2012-09-17 13:54 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2012-09-17 10:49 [PATCH] proc: fix unterminated string Alan Cox
2012-09-17 13:59 ` Alan Cox
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®