diff options
author | Chuck Lever <chuck.lever@oracle.com> | 2022-11-27 18:17:27 +0100 |
---|---|---|
committer | Chuck Lever <cel@kernel.org> | 2022-12-10 17:01:13 +0100 |
commit | 4dd9daa9124aad3c3d4ceca4f1d417cc62d59156 (patch) | |
tree | 8303c8dad42987d5a6c978df4bd0e587f629587f /ipc/mqueue.c | |
parent | SUNRPC: Make the svc_authenticate tracepoint conditional (diff) | |
download | linux-4dd9daa9124aad3c3d4ceca4f1d417cc62d59156.tar.xz linux-4dd9daa9124aad3c3d4ceca4f1d417cc62d59156.zip |
SUNRPC: Fix crasher in unwrap_integ_data()
If a zero length is passed to kmalloc() it returns 0x10, which is
not a valid address. gss_verify_mic() subsequently crashes when it
attempts to dereference that pointer.
Instead of allocating this memory on every call based on an
untrusted size value, use a piece of dynamically-allocated scratch
memory that is always available.
Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
Reviewed-by: Jeff Layton <jlayton@kernel.org>
Diffstat (limited to 'ipc/mqueue.c')
0 files changed, 0 insertions, 0 deletions