mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
synced 2024-09-29 13:53:33 +00:00
ipv4: ARP neigh procfs buffer overflow
If arp_format_neigh_entry() can be called with n->dev->addr_len == 0, then a write to hbuffer[-1] occurs. Signed-off-by: Roel Kluin <roel.kluin@gmail.com> Signed-off-by: David S. Miller <davem@davemloft.net>
This commit is contained in:
parent
3d54015b75
commit
a3e8ee6820
1 changed files with 3 additions and 1 deletions
|
@ -1304,7 +1304,9 @@ static void arp_format_neigh_entry(struct seq_file *seq,
|
||||||
hbuffer[k++] = hex_asc_lo(n->ha[j]);
|
hbuffer[k++] = hex_asc_lo(n->ha[j]);
|
||||||
hbuffer[k++] = ':';
|
hbuffer[k++] = ':';
|
||||||
}
|
}
|
||||||
hbuffer[--k] = 0;
|
if (k != 0)
|
||||||
|
--k;
|
||||||
|
hbuffer[k] = 0;
|
||||||
#if defined(CONFIG_AX25) || defined(CONFIG_AX25_MODULE)
|
#if defined(CONFIG_AX25) || defined(CONFIG_AX25_MODULE)
|
||||||
}
|
}
|
||||||
#endif
|
#endif
|
||||||
|
|
Loading…
Reference in a new issue