diff options
author | Vasiliy Kulikov <[email protected]> | 2011-02-14 13:54:31 +0300 |
---|---|---|
committer | Gustavo F. Padovan <[email protected]> | 2011-02-14 12:51:33 -0200 |
commit | 43629f8f5ea32a998d06d1bb41eefa0e821ff573 (patch) | |
tree | 6cc475d80311abf2b06e2b8a2cfd96043192decd /lib/genalloc.c | |
parent | d9f51b51db2064c9049bf7924318fd8c6ed852cb (diff) |
Bluetooth: bnep: fix buffer overflow
Struct ca is copied from userspace. It is not checked whether the "device"
field is NULL terminated. This potentially leads to BUG() inside of
alloc_netdev_mqs() and/or information leak by creating a device with a name
made of contents of kernel stack.
Signed-off-by: Vasiliy Kulikov <[email protected]>
Signed-off-by: Gustavo F. Padovan <[email protected]>
Diffstat (limited to 'lib/genalloc.c')
0 files changed, 0 insertions, 0 deletions