Thread (2 messages) flat view 2 messages, 2 authors, 2012-07-22

Re: [PATCH] net: Fix references to out-of-scope variables in put_cmsg_compat()

From: David Miller <davem@davemloft.net>
Date: 2012-07-22 21:54:09
Also in: lkml

From: Jesper Juhl <redacted>
Date: Sun, 22 Jul 2012 23:37:20 +0200 (CEST)
In net/compat.c::put_cmsg_compat() we may assign 'data' the address of
either the 'ctv' or 'cts' local variables inside the 'if
(!COMPAT_USE_64BIT_TIME)' branch.

Those variables go out of scope at the end of the 'if' statement, so
when we use 'data' further down in 'copy_to_user(CMSG_COMPAT_DATA(cm),
data, cmlen - sizeof(struct compat_cmsghdr))' there's no telling what
it may be refering to - not good.

Fix the problem by simply giving 'ctv' and 'cts' function scope.

Signed-off-by: Jesper Juhl <redacted>
Applied and queued up for -stable, thanks.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help