From: Sasha Levin Date: Tue, 3 Feb 2015 13:55:58 +0000 (-0500) Subject: net: rds: use correct size for max unacked packets and bytes X-Git-Tag: v3.16.35~2672 X-Git-Url: http://git.ipfire.org/gitweb.cgi?a=commitdiff_plain;h=065f373545d11d7dfe22d6fa1381b214522f187a;p=thirdparty%2Fkernel%2Fstable.git net: rds: use correct size for max unacked packets and bytes commit db27ebb111e9f69efece08e4cb6a34ff980f8896 upstream. Max unacked packets/bytes is an int while sizeof(long) was used in the sysctl table. This means that when they were getting read we'd also leak kernel memory to userspace along with the timeout values. Signed-off-by: Sasha Levin Signed-off-by: David S. Miller Cc: Moritz Muehlenhoff Signed-off-by: Luis Henriques --- diff --git a/net/rds/sysctl.c b/net/rds/sysctl.c index c3b0cd43eb566..c173f69e1479b 100644 --- a/net/rds/sysctl.c +++ b/net/rds/sysctl.c @@ -71,14 +71,14 @@ static struct ctl_table rds_sysctl_rds_table[] = { { .procname = "max_unacked_packets", .data = &rds_sysctl_max_unacked_packets, - .maxlen = sizeof(unsigned long), + .maxlen = sizeof(int), .mode = 0644, .proc_handler = proc_dointvec, }, { .procname = "max_unacked_bytes", .data = &rds_sysctl_max_unacked_bytes, - .maxlen = sizeof(unsigned long), + .maxlen = sizeof(int), .mode = 0644, .proc_handler = proc_dointvec, },