mirror of
https://github.com/torvalds/linux.git
synced 2026-10-07 05:31:08 -04:00
exec.c, compat.c: fix count(), compat_count() bounds checking
With MAX_ARG_STRINGS set to 0x7FFFFFFF, and being passed to 'count()' and compat_count(), it would appear that the current max bounds check of fs/exec.c:394: if(++i > max) return -E2BIG; would never trigger. Since 'i' is of type int, so values would wrap and the function would continue looping. Simple fix seems to be chaning ++i to i++ and checking for '>='. Signed-off-by: Jason Baron <[email protected]> Acked-by: Peter Zijlstra <[email protected]> Cc: "Ollie Wild" <[email protected]> Signed-off-by: Andrew Morton <[email protected]> Signed-off-by: Linus Torvalds <[email protected]>
This commit is contained in:
1 parent
9679e4dd62
commit
362e6663ef
2 files changed
+2
-2
No files matched your search
+1
-1
@@ -1239,7 +1239,7 @@ static int compat_count(compat_uptr_t __user *argv, int max)
|
||||
if (!p)
|
||||
break;
|
||||
argv++;
|
||||
if(++i > max)
|
||||
if (i++ >= max)
|
||||
return -E2BIG;
|
||||
}
|
||||
}
|
||||
|
||||
Reference in new issue
Block a user