diff options
author | Dan Carpenter <dan.carpenter@oracle.com> | 2012-01-18 10:56:02 +0100 |
---|---|---|
committer | J. Bruce Fields <bfields@redhat.com> | 2012-02-03 20:26:42 +0100 |
commit | 6d8d17499810479eabd10731179c04b2ca22152f (patch) | |
tree | b0c0324a0735ee98fc967ff034fc60e8035cdac8 | |
parent | Linux 3.3-rc2 (diff) | |
download | linux-6d8d17499810479eabd10731179c04b2ca22152f.tar.xz linux-6d8d17499810479eabd10731179c04b2ca22152f.zip |
nfsd: don't allow zero length strings in cache_parse()
There is no point in passing a zero length string here and quite a
few of that cache_parse() implementations will Oops if count is
zero.
Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
Cc: stable@kernel.org
Signed-off-by: J. Bruce Fields <bfields@redhat.com>
-rw-r--r-- | net/sunrpc/cache.c | 2 |
1 files changed, 2 insertions, 0 deletions
diff --git a/net/sunrpc/cache.c b/net/sunrpc/cache.c index 465df9ae1046..8c6598e0334a 100644 --- a/net/sunrpc/cache.c +++ b/net/sunrpc/cache.c @@ -828,6 +828,8 @@ static ssize_t cache_do_downcall(char *kaddr, const char __user *buf, { ssize_t ret; + if (count == 0) + return -EINVAL; if (copy_from_user(kaddr, buf, count)) return -EFAULT; kaddr[count] = '\0'; |