]> git.ipfire.org Git - thirdparty/kernel/stable.git/commit
sxgbe: Fix off by one in samsung driver strncpy size arg
authorDominik Czarnota <dominik.b.czarnota@gmail.com>
Mon, 9 Mar 2020 15:22:50 +0000 (16:22 +0100)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Wed, 1 Apr 2020 09:00:01 +0000 (11:00 +0200)
commit1ca96ac200c8e7a589ac69f3b1675fd18ed9e5bc
treedea027d568ac151326ab84f49d6669e2afaf311b
parent66deedad8d92632b149f6745b8ee452a8397afa8
sxgbe: Fix off by one in samsung driver strncpy size arg

[ Upstream commit f3cc008bf6d59b8d93b4190e01d3e557b0040e15 ]

This patch fixes an off-by-one error in strncpy size argument in
drivers/net/ethernet/samsung/sxgbe/sxgbe_main.c. The issue is that in:

        strncmp(opt, "eee_timer:", 6)

the passed string literal: "eee_timer:" has 10 bytes (without the NULL
byte) and the passed size argument is 6. As a result, the logic will
also accept other, malformed strings, e.g. "eee_tiXXX:".

This bug doesn't seem to have any security impact since its present in
module's cmdline parsing code.

Signed-off-by: Dominik Czarnota <dominik.b.czarnota@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
drivers/net/ethernet/samsung/sxgbe/sxgbe_main.c