[PATCH 56/91] hfs: add sanity check for file name length

From: Willy Tarreau
Date: Sun Feb 05 2012 - 17:40:14 EST


2.6.27-longterm review patch. If anyone has any objections, please let us know.

------------------

commit bc5b8a9003132ae44559edd63a1623b7b99dfb68 upstream.

On a corrupted file system the ->len field could be wrong leading to
a buffer overflow.

Reported-and-acked-by: Clement LECIGNE <clement.lecigne@xxxxxxxxxx>
Signed-off-by: Dan Carpenter <dan.carpenter@xxxxxxxxxx>
Signed-off-by: Linus Torvalds <torvalds@xxxxxxxxxxxxxxxxxxxx>
Signed-off-by: Greg Kroah-Hartman <gregkh@xxxxxxx>
---
fs/hfs/trans.c | 2 ++
1 files changed, 2 insertions(+), 0 deletions(-)

Index: longterm-2.6.27/fs/hfs/trans.c
===================================================================
--- longterm-2.6.27.orig/fs/hfs/trans.c 2012-02-05 22:34:33.296915074 +0100
+++ longterm-2.6.27/fs/hfs/trans.c 2012-02-05 22:34:42.844914477 +0100
@@ -40,6 +40,8 @@

src = in->name;
srclen = in->len;
+ if (srclen > HFS_NAMELEN)
+ srclen = HFS_NAMELEN;
dst = out;
dstlen = HFS_MAX_NAMELEN;
if (nls_io) {


--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/