summaryrefslogtreecommitdiff
path: root/drivers/mfd/axp20x-rsb.c
diff options
context:
space:
mode:
authorAl Viro <viro@zeniv.linux.org.uk>2017-01-15 03:33:08 +0300
committerAl Viro <viro@zeniv.linux.org.uk>2017-01-15 03:50:41 +0300
commitb9dc6f65bc5e232d1c05fe34b5daadc7e8bbf1fb (patch)
treeca221e796b274a6c909db003fcda215156aa4cc7 /drivers/mfd/axp20x-rsb.c
parent4d22c75d4c7b5c5f4bd31054f09103ee490878fd (diff)
downloadlinux-b9dc6f65bc5e232d1c05fe34b5daadc7e8bbf1fb.tar.xz
fix a fencepost error in pipe_advance()
The logics in pipe_advance() used to release all buffers past the new position failed in cases when the number of buffers to release was equal to pipe->buffers. If that happened, none of them had been released, leaving pipe full. Worse, it was trivial to trigger and we end up with pipe full of uninitialized pages. IOW, it's an infoleak. Cc: stable@vger.kernel.org # v4.9 Reported-by: "Alan J. Wylie" <alan@wylie.me.uk> Tested-by: "Alan J. Wylie" <alan@wylie.me.uk> Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
Diffstat (limited to 'drivers/mfd/axp20x-rsb.c')
0 files changed, 0 insertions, 0 deletions