From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S933073Ab1JZM6q (ORCPT ); Wed, 26 Oct 2011 08:58:46 -0400 Received: from cantor2.suse.de ([195.135.220.15]:36697 "EHLO mx2.suse.de" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S932967Ab1JZM6p (ORCPT ); Wed, 26 Oct 2011 08:58:45 -0400 Date: Wed, 26 Oct 2011 14:58:43 +0200 Message-ID: From: Takashi Iwai To: Alexander Stein Cc: Jaroslav Kysela , alsa-devel@alsa-project.org, linux-kernel@vger.kernel.org Subject: Re: [PATCH] hda_hwdep: Fix possible buffer overflow In-Reply-To: <1319615292-27396-1-git-send-email-alexander.stein@systec-electronic.com> References: <1319615292-27396-1-git-send-email-alexander.stein@systec-electronic.com> User-Agent: Wanderlust/2.15.6 (Almost Unreal) SEMI/1.14.6 (Maruoka) FLIM/1.14.9 (=?UTF-8?B?R29qxY0=?=) APEL/10.7 Emacs/23.3 (x86_64-suse-linux-gnu) MULE/6.0 (HANACHIRUSATO) MIME-Version: 1.0 (generated by SEMI 1.14.6 - "Maruoka") Content-Type: text/plain; charset=US-ASCII Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org At Wed, 26 Oct 2011 09:48:12 +0200, Alexander Stein wrote: > > If a line in the firmware file is larger than the given buffer size (and > so the firmware file size), size is set to a value larger than the actual > buffer size. This results in an overflow in the buffer passed. > Fix this by copying only up to 127 chars per line. Actually this check should have been if (size > fw->size) size = fw->size; Otherwise it doesn't make sense. If the change is OK, could you resend the patch with it? thanks, Takashi > Signed-off-by: Alexander Stein > --- > sound/pci/hda/hda_hwdep.c | 6 +++--- > 1 files changed, 3 insertions(+), 3 deletions(-) > > diff --git a/sound/pci/hda/hda_hwdep.c b/sound/pci/hda/hda_hwdep.c > index bf3ced5..61da08d 100644 > --- a/sound/pci/hda/hda_hwdep.c > +++ b/sound/pci/hda/hda_hwdep.c > @@ -745,6 +745,7 @@ static int parse_line_mode(char *buf, struct hda_bus *bus) > * if successfully copied a line > * > * the spaces at the beginning and the end of the line are stripped > + * lines read are clamped to 127 chars > */ > static int get_line_from_fw(char *buf, int size, struct firmware *fw) > { > @@ -756,8 +757,6 @@ static int get_line_from_fw(char *buf, int size, struct firmware *fw) > } > if (!fw->size) > return 0; > - if (size < fw->size) > - size = fw->size; > > for (len = 0; len < fw->size; len++) { > if (!*p) > @@ -768,7 +767,8 @@ static int get_line_from_fw(char *buf, int size, struct firmware *fw) > break; > } > if (len < size) > - *buf++ = *p++; > + *buf++ = *p; > + p++; > } > *buf = 0; > fw->size -= len; > -- > 1.7.3.4 >