No description
Find a file
Lasse Collin 543d8854c4 lib/xz: Avoid overlapping memcpy() with invalid input with in-place decompression
[ Upstream commit 83d3c4f22a ]

With valid files, the safety margin described in lib/decompress_unxz.c
ensures that these buffers cannot overlap. But if the uncompressed size
of the input is larger than the caller thought, which is possible when
the input file is invalid/corrupt, the buffers can overlap. Obviously
the result will then be garbage (and usually the decoder will return
an error too) but no other harm will happen when such an over-run occurs.

This change only affects uncompressed LZMA2 chunks and so this
should have no effect on performance.

Link: https://lore.kernel.org/r/20211010213145.17462-2-xiang@kernel.org
Signed-off-by: Lasse Collin <lasse.collin@tukaani.org>
Signed-off-by: Gao Xiang <hsiangkao@linux.alibaba.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2021-11-26 11:36:06 +01:00
arch ia64: don't do IA64_CMPXCHG_DEBUG without CONFIG_PRINTK 2021-11-26 11:36:05 +01:00
block Revert "block, bfq: honor already-setup queue merges" 2021-10-06 15:31:23 +02:00
certs certs: Trigger creation of RSA module signing key if it's not an RSA key 2021-09-22 11:47:51 +02:00
crypto crypto: shash - avoid comparing pointers to exported functions under CFI 2021-07-20 16:15:44 +02:00
Documentation xen/balloon: add late_initcall_sync() for initial ballooning done 2021-11-26 11:36:02 +01:00
drivers memstick: r592: Fix a UAF bug when removing the driver 2021-11-26 11:36:06 +01:00
firmware
fs tracefs: Have tracefs directories not set OTH permission bits by default 2021-11-26 11:36:05 +01:00
include net: sched: update default qdisc visibility after Tx queue cnt changes 2021-11-26 11:36:04 +01:00
init pid: take a reference when initializing cad_pid 2021-06-10 13:24:06 +02:00
ipc ipc/util.c: sysvipc_find_ipc() incorrectly updates position index 2020-05-20 08:18:40 +02:00
kernel locking/lockdep: Avoid RCU-induced noinstr fail 2021-11-26 11:36:04 +01:00
lib lib/xz: Avoid overlapping memcpy() with invalid input with in-place decompression 2021-11-26 11:36:06 +01:00
LICENSES
mm mm, slub: fix mismatch between reconstructed freelist depth and cnt 2021-10-27 09:53:14 +02:00
net net: sched: update default qdisc visibility after Tx queue cnt changes 2021-11-26 11:36:04 +01:00
samples samples: bpf: Fix tracex7 error raised on the missing argument 2021-09-22 11:48:05 +02:00
scripts leaking_addresses: Always print a trailing newline 2021-11-26 11:36:06 +01:00
security smackfs: Fix use-after-free in netlbl_catmap_walk() 2021-11-26 11:36:04 +01:00
sound ALSA: mixer: fix deadlock in snd_mixer_oss_set_volume 2021-11-26 11:36:02 +01:00
tools tools/vm/page-types: remove dependency on opt_file for idle page tracking 2021-10-09 14:11:03 +02:00
usr
virt KVM: remember position in kvm->vcpus array 2021-09-26 13:39:46 +02:00
.clang-format
.cocciconfig
.get_maintainer.ignore
.gitattributes
.gitignore
.mailmap
COPYING
CREDITS
Kbuild
Kconfig
MAINTAINERS Documentation/llvm: add documentation on building w/ Clang/LLVM 2020-09-26 18:01:31 +02:00
Makefile Linux 4.19.217 2021-11-12 14:40:52 +01:00
README

Linux kernel
============

There are several guides for kernel developers and users. These guides can
be rendered in a number of formats, like HTML and PDF. Please read
Documentation/admin-guide/README.rst first.

In order to build the documentation, use ``make htmldocs`` or
``make pdfdocs``.  The formatted documentation can also be read online at:

    https://www.kernel.org/doc/html/latest/

There are various text files in the Documentation/ subdirectory,
several of them using the Restructured Text markup notation.
See Documentation/00-INDEX for a list of what is contained in each file.

Please read the Documentation/process/changes.rst file, as it contains the
requirements for building and running the kernel, and information about
the problems which may result by upgrading your kernel.