diff options
| author | Zhang Shurong <zhang_shurong@foxmail.com> | 2023-07-09 08:50:07 +0300 | 
|---|---|---|
| committer | Greg Kroah-Hartman <gregkh@linuxfoundation.org> | 2023-07-27 10:54:33 +0300 | 
| commit | 5f1c7031e044cb2fba82836d55cc235e2ad619dc (patch) | |
| tree | bdd7bd8aa7c5e54ee11c2b548b8ee5f34986e316 /net/unix/diag.c | |
| parent | 4912649e1cf0317bf563f91655e04a303cacaf8d (diff) | |
| download | linux-5f1c7031e044cb2fba82836d55cc235e2ad619dc.tar.xz | |
staging: ks7010: potential buffer overflow in ks_wlan_set_encode_ext()
The "exc->key_len" is a u16 that comes from the user.  If it's over
IW_ENCODING_TOKEN_MAX (64) that could lead to memory corruption.
Fixes: b121d84882b9 ("staging: ks7010: simplify calls to memcpy()")
Cc: stable <stable@kernel.org>
Signed-off-by: Zhang Shurong <zhang_shurong@foxmail.com>
Reviewed-by: Dan Carpenter <dan.carpenter@linaro.org>
Link: https://lore.kernel.org/r/tencent_5153B668C0283CAA15AA518325346E026A09@qq.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Diffstat (limited to 'net/unix/diag.c')
0 files changed, 0 insertions, 0 deletions
