Thread (315 messages) flat view 315 messages, 7 authors, 2016-11-12
STALE3553d

[PATCH 3.16 278/305] ALSA: timer: Fix leak in events via snd_timer_user_ccallback

From: Ben Hutchings <hidden>
Date: 2016-08-14 10:57:53
Also in: lkml

3.16.37-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Kangjie Lu <redacted>

commit 9a47e9cff994f37f7f0dbd9ae23740d0f64f9fe6 upstream.

The stack object “r1” has a total size of 32 bytes. Its field
“event” and “val” both contain 4 bytes padding. These 8 bytes
padding bytes are sent to user without being initialized.

Signed-off-by: Kangjie Lu <redacted>
Signed-off-by: Takashi Iwai <redacted>
Signed-off-by: Ben Hutchings <redacted>
---
 sound/core/timer.c | 1 +
 1 file changed, 1 insertion(+)
--- a/sound/core/timer.c
+++ b/sound/core/timer.c
@@ -1251,6 +1251,7 @@ static void snd_timer_user_ccallback(str
 		tu->tstamp = *tstamp;
 	if ((tu->filter & (1 << event)) == 0 || !tu->tread)
 		return;
+	memset(&r1, 0, sizeof(r1));
 	r1.event = event;
 	r1.tstamp = *tstamp;
 	r1.val = resolution;
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help