* [PATCH] um: mconsole: use bounded version string formatting
@ 2026-03-29 3:09 Pengpeng Hou
2026-04-08 7:29 ` Johannes Berg
2026-04-08 7:35 ` [PATCH v2] " Pengpeng Hou
0 siblings, 2 replies; 3+ messages in thread
From: Pengpeng Hou @ 2026-03-29 3:09 UTC (permalink / raw)
To: richard, anton.ivanov, johannes
Cc: akpm, sergeh, clg, linux-um, linux-kernel, pengpeng
mconsole_version() formats several UTS strings into a fixed 256-byte local buffer with sprintf() and no length bound.
Use snprintf() so the version reply stays within the local buffer.
Fixes: e9ff3990f08e ("[PATCH] namespaces: utsname: switch to using uts namespaces")
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
---
arch/um/drivers/mconsole_kern.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/arch/um/drivers/mconsole_kern.c b/arch/um/drivers/mconsole_kern.c
index e2a9e8879f58..18d0ec15557c 100644
--- a/arch/um/drivers/mconsole_kern.c
+++ b/arch/um/drivers/mconsole_kern.c
@@ -106,9 +106,9 @@ void mconsole_version(struct mc_request *req)
{
char version[256];
- sprintf(version, "%s %s %s %s %s", utsname()->sysname,
- utsname()->nodename, utsname()->release, utsname()->version,
- utsname()->machine);
+ snprintf(version, sizeof(version), "%s %s %s %s %s",
+ utsname()->sysname, utsname()->nodename, utsname()->release,
+ utsname()->version, utsname()->machine);
mconsole_reply(req, version, 0, 0);
}
--
2.50.1 (Apple Git-155)
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH] um: mconsole: use bounded version string formatting
2026-03-29 3:09 [PATCH] um: mconsole: use bounded version string formatting Pengpeng Hou
@ 2026-04-08 7:29 ` Johannes Berg
2026-04-08 7:35 ` [PATCH v2] " Pengpeng Hou
1 sibling, 0 replies; 3+ messages in thread
From: Johannes Berg @ 2026-04-08 7:29 UTC (permalink / raw)
To: Pengpeng Hou, richard, anton.ivanov
Cc: akpm, sergeh, clg, linux-um, linux-kernel
On Sun, 2026-03-29 at 11:09 +0800, Pengpeng Hou wrote:
> mconsole_version() formats several UTS strings into a fixed 256-byte local buffer with sprintf() and no length bound.
You really should line-wrap all your commit messages.
johannes
^ permalink raw reply [flat|nested] 3+ messages in thread
* [PATCH v2] um: mconsole: use bounded version string formatting
2026-03-29 3:09 [PATCH] um: mconsole: use bounded version string formatting Pengpeng Hou
2026-04-08 7:29 ` Johannes Berg
@ 2026-04-08 7:35 ` Pengpeng Hou
1 sibling, 0 replies; 3+ messages in thread
From: Pengpeng Hou @ 2026-04-08 7:35 UTC (permalink / raw)
To: Richard Weinberger, Anton Ivanov, Johannes Berg
Cc: Andrew Morton, Serge E. Hallyn, Christian Borntraeger, linux-um,
linux-kernel, pengpeng
mconsole_version() formats several UTS strings into a fixed 256-byte
local buffer with sprintf() and no length bound.
Use snprintf() so the version reply stays within the local buffer.
Fixes: e9ff3990f08e ("[PATCH] namespaces: utsname: switch to using uts namespaces")
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
---
Changes since v1:
- wrap the changelog paragraphs to 72 columns
---
arch/um/drivers/mconsole_kern.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/arch/um/drivers/mconsole_kern.c b/arch/um/drivers/mconsole_kern.c
index e2a9e8879f58..18d0ec15557c 100644
--- a/arch/um/drivers/mconsole_kern.c
+++ b/arch/um/drivers/mconsole_kern.c
@@ -106,9 +106,9 @@ void mconsole_version(struct mc_request *req)
{
char version[256];
- sprintf(version, "%s %s %s %s %s", utsname()->sysname,
- utsname()->nodename, utsname()->release, utsname()->version,
- utsname()->machine);
+ snprintf(version, sizeof(version), "%s %s %s %s %s",
+ utsname()->sysname, utsname()->nodename, utsname()->release,
+ utsname()->version, utsname()->machine);
mconsole_reply(req, version, 0, 0);
}
--
2.50.1 (Apple Git-155)
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-04-08 8:17 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-03-29 3:09 [PATCH] um: mconsole: use bounded version string formatting Pengpeng Hou
2026-04-08 7:29 ` Johannes Berg
2026-04-08 7:35 ` [PATCH v2] " Pengpeng Hou
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®