diff options
author | Jerry James <loganjerry@gmail.com> | 2018-06-23 23:49:04 +0300 |
---|---|---|
committer | Masahiro Yamada <yamada.masahiro@socionext.com> | 2018-06-28 16:48:08 +0300 |
commit | 73d1c580f92b203f4c3a189ee98c917c65712f7e (patch) | |
tree | f5f4a1a5b4d02a109a2a60feec525d8a5aeb39eb /net/dccp/ipv6.c | |
parent | 8b9d27124094964b3c4f8985ba66355ac4d9e842 (diff) | |
download | linux-73d1c580f92b203f4c3a189ee98c917c65712f7e.tar.xz |
kconfig: loop boundary condition fix
If buf[-1] just happens to hold the byte 0x0A, then nread can wrap around
to (size_t)-1, leading to invalid memory accesses.
This has caused segmentation faults when trying to build the latest
kernel snapshots for i686 in Fedora:
https://bugzilla.redhat.com/show_bug.cgi?id=1592374
Signed-off-by: Jerry James <loganjerry@gmail.com>
[alexpl@fedoraproject.org: reformatted patch for submission]
Signed-off-by: Alexander Ploumistos <alexpl@fedoraproject.org>
Signed-off-by: Masahiro Yamada <yamada.masahiro@socionext.com>
Diffstat (limited to 'net/dccp/ipv6.c')
0 files changed, 0 insertions, 0 deletions