mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2026-07-22 02:17:36 -04:00
dm-ioctl: fix a possible overflow in list_version_get_info
sizeof(tt->version) is 12 bytes, but the code writes 16 bytes into the output buffer - info->vers->version[0], info->vers->version[1], info->vers->version[2] and info->vers->next. This can cause buffer overflow. Fix this buffer overflow by replacing "sizeof(tt->version)" with "sizeof(struct dm_target_versions)". Signed-off-by: Mikulas Patocka <mpatocka@redhat.com> Assisted-by: Claude:claude-opus-4.6 Cc: stable@vger.kernel.org
This commit is contained in:
@@ -785,7 +785,7 @@ static void list_version_get_info(struct target_type *tt, void *param)
|
||||
struct vers_iter *info = param;
|
||||
|
||||
/* Check space - it might have changed since the first iteration */
|
||||
if ((char *)info->vers + sizeof(tt->version) + strlen(tt->name) + 1 > info->end) {
|
||||
if ((char *)info->vers + sizeof(struct dm_target_versions) + strlen(tt->name) + 1 > info->end) {
|
||||
info->flags = DM_BUFFER_FULL_FLAG;
|
||||
return;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user