mirror of https://github.com/torvalds/linux.git
If the server is malicious then *bytes_read could be larger than the size of the "target" buffer. It would lead to memory corruption when we do the memcpy(). Reported-by: Dr Silvio Cesare of InfoSect <Silvio Cesare <silvio.cesare@gmail.com> Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com> Cc: stable <stable@vger.kernel.org> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
||
|---|---|---|
| .. | ||
| android | ||
| board | ||
| ccree | ||
| clocking-wizard | ||
| comedi | ||
| dgnc | ||
| emxx_udc | ||
| fbtft | ||
| fsl-dpaa2 | ||
| fsl-mc | ||
| fwserial | ||
| gdm724x | ||
| goldfish | ||
| greybus | ||
| gs_fpgaboot | ||
| iio | ||
| ipx | ||
| irda | ||
| ks7010 | ||
| lustre | ||
| media | ||
| most | ||
| mt29f_spinand | ||
| ncpfs | ||
| netlogic | ||
| nvec | ||
| octeon | ||
| octeon-usb | ||
| olpc_dcon | ||
| pi433 | ||
| rtl8188eu | ||
| rtl8192e | ||
| rtl8192u | ||
| rtl8712 | ||
| rtl8723bs | ||
| rtlwifi | ||
| rts5208 | ||
| skein | ||
| sm750fb | ||
| speakup | ||
| typec | ||
| unisys | ||
| vboxvideo | ||
| vc04_services | ||
| vme | ||
| vt6655 | ||
| vt6656 | ||
| wilc1000 | ||
| wlan-ng | ||
| xgifb | ||
| Kconfig | ||
| Makefile | ||