mirror of
https://github.com/torvalds/linux.git
synced 2024-12-05 02:23:16 +00:00
b530fb69cf
setup.phone and setup.eazmsn are 32 character buffers. rcvmsg.msg_data.byte_array is a 48 character buffer. sc_adapter[card]->channel[rcvmsg.phy_link_no - 1].dn is 50 chars. The rcvmsg struct comes from the memcpy_fromio() in receivemessage(). I guess that means it's data off the wire. I'm not very familiar with this code but I don't see any reason to assume these strings are NULL terminated. Also it's weird that "dn" in a 50 character buffer but we only seem to use 32 characters. In drivers/isdn/sc/scioc.h, "dn" is only a 49 character buffer. So potentially there is still an issue there. The important thing for now is to prevent the memory corruption. Signed-off-by: Dan Carpenter <error27@gmail.com> Signed-off-by: David S. Miller <davem@davemloft.net> |
||
---|---|---|
.. | ||
card.h | ||
command.c | ||
event.c | ||
hardware.h | ||
includes.h | ||
init.c | ||
interrupt.c | ||
ioctl.c | ||
Kconfig | ||
Makefile | ||
message.c | ||
message.h | ||
packet.c | ||
scioc.h | ||
shmem.c | ||
timer.c |