From: "Jesper Juhl" <jesper.juhl@gmail.com>
To: "Andrew Morton" <akpm@linux-foundation.org>
Cc: "Richard Henderson" <rth@tamu.edu>,
"Linux Kernel Mailing List" <linux-kernel@vger.kernel.org>
Subject: Re: [PATCH] Avoid potential NULL deref in scripts/genksyms/lex.l
Date: Mon, 25 Jun 2007 00:02:03 +0200 [thread overview]
Message-ID: <9a8748490706241502j217a5c6drd015dcd84633ab3a@mail.gmail.com> (raw)
In-Reply-To: <20070624145837.f3141572.akpm@linux-foundation.org>
On 24/06/07, Andrew Morton <akpm@linux-foundation.org> wrote:
> On Sun, 24 Jun 2007 23:40:03 +0200 Jesper Juhl <jesper.juhl@gmail.com> wrote:
>
> > strchr() returns NULL in case the string is not found and if that
> > happens we risk dereferencing a NULL pointer. It never hurts to
> > check for that condition and exit normally with an error rather
> > than crashing.
> >
> > (no, the indentation is not according to CodingStyle, it's simply
> > following whatever else is in that file)
> >
> >
> > Signed-off-by: Jesper Juhl <jesper.juhl@gmail.com>
> > ---
> >
> > scripts/genksyms/lex.l | 2 ++
> > 1 files changed, 2 insertions(+), 0 deletions(-)
> >
> > diff --git a/scripts/genksyms/lex.l b/scripts/genksyms/lex.l
> > index 5e544a0..28edc0c 100644
> > --- a/scripts/genksyms/lex.l
> > +++ b/scripts/genksyms/lex.l
> > @@ -154,6 +154,8 @@ repeat:
> >
> > file = strchr(yytext, '\"')+1;
> > e = strchr(file, '\"');
>
> If `file' can be null we'd have oopsed here.
>
> > + if (!file || !e)
> > + exit(1);
> > *e = '\0';
> > cur_filename = memcpy(xmalloc(e-file+1), file, e-file+1);
> > cur_line = atoi(yytext+2);
>
> I don't think the bug which you're fixing can occur:
>
> ^#[ \t]+{INT}[ \t]+\"[^\"\n]+\".*\n return FILENAME;
>
> has anyone reported crashes in there?
>
It may indeed not be possible. Found by inspection, not by any actual
observed crashes.
But does it really hurt to be defensive here? In case it can somehow
be caused to fail, with my patch it'll fail a bit nicer :) It's not
like it's at all speed critical code that will be hurt by that extra
'if'...
--
Jesper Juhl <jesper.juhl@gmail.com>
Don't top-post http://www.catb.org/~esr/jargon/html/T/top-post.html
Plain text mails only, please http://www.expita.com/nomime.html
next prev parent reply other threads:[~2007-06-24 22:02 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2007-06-24 21:40 Jesper Juhl
2007-06-24 21:58 ` Andrew Morton
2007-06-24 22:02 ` Jesper Juhl [this message]
2007-06-24 23:00 ` Andrew Morton
2007-06-24 23:08 ` Jesper Juhl
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=9a8748490706241502j217a5c6drd015dcd84633ab3a@mail.gmail.com \
--to=jesper.juhl@gmail.com \
--cc=akpm@linux-foundation.org \
--cc=linux-kernel@vger.kernel.org \
--cc=rth@tamu.edu \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®