From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-12.8 required=3.0 tests=BAYES_00, HEADER_FROM_DIFFERENT_DOMAINS,INCLUDES_PATCH,MAILING_LIST_MULTI,SIGNED_OFF_BY, SPF_HELO_NONE,SPF_PASS,URIBL_BLOCKED,USER_AGENT_GIT autolearn=ham autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id A75F1C2D0A3 for ; Mon, 9 Nov 2020 13:36:22 +0000 (UTC) Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by mail.kernel.org (Postfix) with ESMTP id 6B8C220658 for ; Mon, 9 Nov 2020 13:36:22 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1731536AbgKINgV (ORCPT ); Mon, 9 Nov 2020 08:36:21 -0500 Received: from youngberry.canonical.com ([91.189.89.112]:51656 "EHLO youngberry.canonical.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1730753AbgKINEv (ORCPT ); Mon, 9 Nov 2020 08:04:51 -0500 Received: from 1.general.cking.uk.vpn ([10.172.193.212] helo=localhost) by youngberry.canonical.com with esmtpsa (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.86_2) (envelope-from ) id 1kc6ql-0006it-A6; Mon, 09 Nov 2020 13:04:47 +0000 From: Colin King To: Paul Gortmaker , "Paul E . McKenney" Cc: kernel-janitors@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH][next] cpumask: allocate enough space for string and trailing '\0' char Date: Mon, 9 Nov 2020 13:04:47 +0000 Message-Id: <20201109130447.2080491-1-colin.king@canonical.com> X-Mailer: git-send-email 2.28.0 MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 8bit Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org From: Colin Ian King Currently the allocation of cpulist is based on the length of buf but does not include the addition end of string '\0' terminator. Static analysis is reporting this as a potential out-of-bounds access on cpulist. Fix this by allocating enough space for the additional '\0' terminator. Addresses-Coverity: ("Out-of-bounds access") Fixes: 65987e67f7ff ("cpumask: add "last" alias for cpu list specifications") Signed-off-by: Colin Ian King --- lib/cpumask.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/lib/cpumask.c b/lib/cpumask.c index 34ecb3005941..cb8a3ef0e73e 100644 --- a/lib/cpumask.c +++ b/lib/cpumask.c @@ -185,7 +185,7 @@ int __ref cpulist_parse(const char *buf, struct cpumask *dstp) { int r; char *cpulist, last_cpu[5]; /* NR_CPUS <= 9999 */ - size_t len = strlen(buf); + size_t len = strlen(buf) + 1; bool early = !slab_is_available(); if (!strcmp(buf, "all")) { -- 2.28.0