diff options
| author | Chuck Lever <chuck.lever@oracle.com> | 2022-11-27 12:17:27 -0500 | 
|---|---|---|
| committer | Chuck Lever <cel@kernel.org> | 2022-12-10 11:01:13 -0500 | 
| commit | 4dd9daa9124aad3c3d4ceca4f1d417cc62d59156 (patch) | |
| tree | 8303c8dad42987d5a6c978df4bd0e587f629587f /net/lapb/lapb_out.c | |
| parent | c65d9df0c4a0e150d97aff363cbd0363f21f9466 (diff) | |
SUNRPC: Fix crasher in unwrap_integ_data()
If a zero length is passed to kmalloc() it returns 0x10, which is
not a valid address. gss_verify_mic() subsequently crashes when it
attempts to dereference that pointer.
Instead of allocating this memory on every call based on an
untrusted size value, use a piece of dynamically-allocated scratch
memory that is always available.
Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
Reviewed-by: Jeff Layton <jlayton@kernel.org>
Diffstat (limited to 'net/lapb/lapb_out.c')
0 files changed, 0 insertions, 0 deletions
