mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] udf: fix an uninitialized read bug
@ 2019-04-15 15:26 Wenwen Wang
  2019-04-15 16:05 ` Jan Kara
  0 siblings, 1 reply; 3+ messages in thread
From: Wenwen Wang @ 2019-04-15 15:26 UTC (permalink / raw)
  To: Wenwen Wang; +Cc: Jan Kara, open list

In udf_lookup(), the pointer 'fi' is a local variable initialized by the
return value of the function call udf_find_entry(). However, if the macro
'UDF_RECOVERY' is defined, this variable will become uninitialized if the
else branch is not taken, which can potentially cause incorrect results in
the following execution.

This patch simply initializes this local pointer to NULL.

Signed-off-by: Wenwen Wang <wang6495@umn.edu>
---
 fs/udf/namei.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/fs/udf/namei.c b/fs/udf/namei.c
index 58cc241..9d499e1 100644
--- a/fs/udf/namei.c
+++ b/fs/udf/namei.c
@@ -299,7 +299,7 @@ static struct dentry *udf_lookup(struct inode *dir, struct dentry *dentry,
 	struct inode *inode = NULL;
 	struct fileIdentDesc cfi;
 	struct udf_fileident_bh fibh;
-	struct fileIdentDesc *fi;
+	struct fileIdentDesc *fi = NULL;
 
 	if (dentry->d_name.len > UDF_NAME_LEN)
 		return ERR_PTR(-ENAMETOOLONG);
-- 
2.7.4


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] udf: fix an uninitialized read bug
  2019-04-15 15:26 [PATCH] udf: fix an uninitialized read bug Wenwen Wang
@ 2019-04-15 16:05 ` Jan Kara
  2019-04-15 17:34   ` Wenwen Wang
  0 siblings, 1 reply; 3+ messages in thread
From: Jan Kara @ 2019-04-15 16:05 UTC (permalink / raw)
  To: Wenwen Wang; +Cc: Jan Kara, open list

On Mon 15-04-19 10:26:24, Wenwen Wang wrote:
> In udf_lookup(), the pointer 'fi' is a local variable initialized by the
> return value of the function call udf_find_entry(). However, if the macro
> 'UDF_RECOVERY' is defined, this variable will become uninitialized if the
> else branch is not taken, which can potentially cause incorrect results in
> the following execution.
> 
> This patch simply initializes this local pointer to NULL.
> 
> Signed-off-by: Wenwen Wang <wang6495@umn.edu>

Thanks for the patch! A better fix is to drop the whole UDF_RECOVERY ifdef
and what's in it. It is just dead code anyway.

								Honza

> ---
>  fs/udf/namei.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/fs/udf/namei.c b/fs/udf/namei.c
> index 58cc241..9d499e1 100644
> --- a/fs/udf/namei.c
> +++ b/fs/udf/namei.c
> @@ -299,7 +299,7 @@ static struct dentry *udf_lookup(struct inode *dir, struct dentry *dentry,
>  	struct inode *inode = NULL;
>  	struct fileIdentDesc cfi;
>  	struct udf_fileident_bh fibh;
> -	struct fileIdentDesc *fi;
> +	struct fileIdentDesc *fi = NULL;
>  
>  	if (dentry->d_name.len > UDF_NAME_LEN)
>  		return ERR_PTR(-ENAMETOOLONG);
> -- 
> 2.7.4
> 
> 
-- 
Jan Kara <jack@suse.com>
SUSE Labs, CR

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] udf: fix an uninitialized read bug
  2019-04-15 16:05 ` Jan Kara
@ 2019-04-15 17:34   ` Wenwen Wang
  0 siblings, 0 replies; 3+ messages in thread
From: Wenwen Wang @ 2019-04-15 17:34 UTC (permalink / raw)
  To: Jan Kara; +Cc: Jan Kara, open list, Wenwen Wang

Thanks for your prompt reply, Jan! I will rework the patch.

Best regards,
Wenwen

On Mon, Apr 15, 2019 at 11:05 AM Jan Kara <jack@suse.cz> wrote:
>
> On Mon 15-04-19 10:26:24, Wenwen Wang wrote:
> > In udf_lookup(), the pointer 'fi' is a local variable initialized by the
> > return value of the function call udf_find_entry(). However, if the macro
> > 'UDF_RECOVERY' is defined, this variable will become uninitialized if the
> > else branch is not taken, which can potentially cause incorrect results in
> > the following execution.
> >
> > This patch simply initializes this local pointer to NULL.
> >
> > Signed-off-by: Wenwen Wang <wang6495@umn.edu>
>
> Thanks for the patch! A better fix is to drop the whole UDF_RECOVERY ifdef
> and what's in it. It is just dead code anyway.
>
>                                                                 Honza
>
> > ---
> >  fs/udf/namei.c | 2 +-
> >  1 file changed, 1 insertion(+), 1 deletion(-)
> >
> > diff --git a/fs/udf/namei.c b/fs/udf/namei.c
> > index 58cc241..9d499e1 100644
> > --- a/fs/udf/namei.c
> > +++ b/fs/udf/namei.c
> > @@ -299,7 +299,7 @@ static struct dentry *udf_lookup(struct inode *dir, struct dentry *dentry,
> >       struct inode *inode = NULL;
> >       struct fileIdentDesc cfi;
> >       struct udf_fileident_bh fibh;
> > -     struct fileIdentDesc *fi;
> > +     struct fileIdentDesc *fi = NULL;
> >
> >       if (dentry->d_name.len > UDF_NAME_LEN)
> >               return ERR_PTR(-ENAMETOOLONG);
> > --
> > 2.7.4
> >
> >
> --
> Jan Kara <jack@suse.com>
> SUSE Labs, CR

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2019-04-15 17:43 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2019-04-15 15:26 [PATCH] udf: fix an uninitialized read bug Wenwen Wang
2019-04-15 16:05 ` Jan Kara
2019-04-15 17:34   ` Wenwen Wang

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®