From: Al Viro Date: Fri, 14 Apr 2017 21:22:18 +0000 (-0400) Subject: p9_client_readdir() fix X-Git-Tag: v3.12.74~4 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=a8ece68c56153be505ef9b3ef55e4bcd3cef9331;p=thirdparty%2Fkernel%2Fstable.git p9_client_readdir() fix commit 71d6ad08379304128e4bdfaf0b4185d54375423e upstream. Don't assume that server is sane and won't return more data than asked for. Signed-off-by: Al Viro Signed-off-by: Jiri Slaby --- diff --git a/net/9p/client.c b/net/9p/client.c index ae4778c84559f..bde453ae5e2e5 100644 --- a/net/9p/client.c +++ b/net/9p/client.c @@ -2099,6 +2099,10 @@ int p9_client_readdir(struct p9_fid *fid, char *data, u32 count, u64 offset) trace_9p_protocol_dump(clnt, req->rc); goto free_and_error; } + if (rsize < count) { + pr_err("bogus RREADDIR count (%d > %d)\n", count, rsize); + count = rsize; + } p9_debug(P9_DEBUG_9P, "<<< RREADDIR count %d\n", count);