diff options
author | Chuck Lever <chuck.lever@oracle.com> | 2022-11-27 20:17:27 +0300 |
---|---|---|
committer | Chuck Lever <cel@kernel.org> | 2022-12-10 19:01:13 +0300 |
commit | 4dd9daa9124aad3c3d4ceca4f1d417cc62d59156 (patch) | |
tree | 8303c8dad42987d5a6c978df4bd0e587f629587f /scripts/gcc-plugins/gcc-generate-simple_ipa-pass.h | |
parent | c65d9df0c4a0e150d97aff363cbd0363f21f9466 (diff) | |
download | linux-4dd9daa9124aad3c3d4ceca4f1d417cc62d59156.tar.xz |
SUNRPC: Fix crasher in unwrap_integ_data()
If a zero length is passed to kmalloc() it returns 0x10, which is
not a valid address. gss_verify_mic() subsequently crashes when it
attempts to dereference that pointer.
Instead of allocating this memory on every call based on an
untrusted size value, use a piece of dynamically-allocated scratch
memory that is always available.
Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
Reviewed-by: Jeff Layton <jlayton@kernel.org>
Diffstat (limited to 'scripts/gcc-plugins/gcc-generate-simple_ipa-pass.h')
0 files changed, 0 insertions, 0 deletions