Thread (6 messages) 6 messages, 4 authors, 2020-07-29

Re: [PATCH] vgacon: fix out of bounds write to the scrollback buffer

From: 张云海 <hidden>
Date: 2020-07-29 08:19:07
Also in: dri-devel, lkml

On 2020/7/29 16:11, Jiri Slaby wrote:
But the loop checks for the overflow:
  if (vgacon_scrollback_cur->tail >= vgacon_scrollback_cur->size)
        vgacon_scrollback_cur->tail = 0;

So the first 2 iterations would write to the end of the buffer and this
3rd one should have zeroed ->tail.
In the 2nd  iteration before the check:
vgacon_scrollback_cur->tail is 65360 which is still less then
vgacon_scrollback_cur->size(65440), so the ->tail won't be zeroed.

Then it gose to the 3rd  iteration, overflow occurs.

Regards,
Yunhai Zhang / NSFOCUS Security Team
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help