From: Jesper Juhl <jesper.juhl@gmail.com>
To: Roman Zippel <zippel@linux-m68k.org>
Cc: linux-kernel@vger.kernel.org, Jesper Juhl <jesper.juhl@gmail.com>
Subject: [PATCH] hfs: if match_strdup() fails to allocate memory in parse_options(), don't blow up the kernel.
Date: Tue, 22 Apr 2008 23:12:27 +0200 (CEST) [thread overview]
Message-ID: <alpine.LNX.1.00.0804222309250.14359@dragon.funnycrock.com> (raw)
From: Jesper Juhl <jesper.juhl@gmail.com>
The Coverity checker spotted that we don't check the return value of
match_strdup() in fs/hfs/super.c::parse_options().
This is bad since match_strdup() does a memory allocation internally
which can fail. If it does fail it'll return NULL and in that case
we'll pass the NULL pointer on to load_nls() which will eventually
dereference it - Boom!
Much better to check the return value, fail gracefully and log an
error message if this happens.
This happens in two different spots. I've made the error logged in
each location unique so that it'll be obvious in bug reports later
exactely which one of the two spots got hit (always nice to have
grep'able error messages that point to a unique location in the
source).
Signed-off-by: Jesper Juhl <jesper.juhl@gmail.com>
---
super.c | 8 ++++++++
1 file changed, 8 insertions(+)
diff --git a/fs/hfs/super.c b/fs/hfs/super.c
index 32de44e..221e314 100644
--- a/fs/hfs/super.c
+++ b/fs/hfs/super.c
@@ -297,6 +297,10 @@ static int parse_options(char *options, struct hfs_sb_info *hsb)
return 0;
}
p = match_strdup(&args[0]);
+ if (!p) {
+ printk(KERN_ERR "hfs: mem alloc failed in match_strdup()\n");
+ return 0;
+ }
hsb->nls_disk = load_nls(p);
if (!hsb->nls_disk) {
printk(KERN_ERR "hfs: unable to load codepage \"%s\"\n", p);
@@ -311,6 +315,10 @@ static int parse_options(char *options, struct hfs_sb_info *hsb)
return 0;
}
p = match_strdup(&args[0]);
+ if (!p) {
+ printk(KERN_ERR "hfs: memory allocation failed in match_strdup()\n");
+ return 0;
+ }
hsb->nls_io = load_nls(p);
if (!hsb->nls_io) {
printk(KERN_ERR "hfs: unable to load iocharset \"%s\"\n", p);
next reply other threads:[~2008-04-22 21:12 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2008-04-22 21:12 Jesper Juhl [this message]
2008-04-22 21:17 ` Joe Perches
2008-04-22 21:21 ` Jesper Juhl
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=alpine.LNX.1.00.0804222309250.14359@dragon.funnycrock.com \
--to=jesper.juhl@gmail.com \
--cc=linux-kernel@vger.kernel.org \
--cc=zippel@linux-m68k.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®