aboutsummaryrefslogtreecommitdiff
path: root/scripts/gdb/linux/mm.py
diff options
context:
space:
mode:
authorFelix Fietkau <[email protected]>2020-02-20 12:41:39 +0100
committerKalle Valo <[email protected]>2020-03-03 17:30:25 +0200
commitb102f0c522cf668c8382c56a4f771b37d011cda2 (patch)
tree7241c52d1e25587c46fe14df15ee207c0c11eeaf /scripts/gdb/linux/mm.py
parenta9149d243f259ad8f02b1e23dfe8ba06128f15e1 (diff)
mt76: fix array overflow on receiving too many fragments for a packet
If the hardware receives an oversized packet with too many rx fragments, skb_shinfo(skb)->frags can overflow and corrupt memory of adjacent pages. This becomes especially visible if it corrupts the freelist pointer of a slab page. Cc: [email protected] Signed-off-by: Felix Fietkau <[email protected]> Signed-off-by: Kalle Valo <[email protected]>
Diffstat (limited to 'scripts/gdb/linux/mm.py')
0 files changed, 0 insertions, 0 deletions