From patchwork Thu Jan 17 07:44:05 2013 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Dan Carpenter X-Patchwork-Id: 213156 X-Patchwork-Delegate: davem@davemloft.net Return-Path: X-Original-To: patchwork-incoming@ozlabs.org Delivered-To: patchwork-incoming@ozlabs.org Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by ozlabs.org (Postfix) with ESMTP id 6AEBF2C0086 for ; Thu, 17 Jan 2013 18:44:18 +1100 (EST) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1759142Ab3AQHoI (ORCPT ); Thu, 17 Jan 2013 02:44:08 -0500 Received: from userp1040.oracle.com ([156.151.31.81]:27859 "EHLO userp1040.oracle.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1753930Ab3AQHoH (ORCPT ); Thu, 17 Jan 2013 02:44:07 -0500 Received: from ucsinet21.oracle.com (ucsinet21.oracle.com [156.151.31.93]) by userp1040.oracle.com (Sentrion-MTA-4.2.2/Sentrion-MTA-4.2.2) with ESMTP id r0H7hooC020130 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=OK); Thu, 17 Jan 2013 07:43:50 GMT Received: from acsmt356.oracle.com (acsmt356.oracle.com [141.146.40.156]) by ucsinet21.oracle.com (8.14.4+Sun/8.14.4) with ESMTP id r0H7hn2q021171 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 17 Jan 2013 07:43:49 GMT Received: from abhmt107.oracle.com (abhmt107.oracle.com [141.146.116.59]) by acsmt356.oracle.com (8.12.11.20060308/8.12.11) with ESMTP id r0H7hm2b010906; Thu, 17 Jan 2013 01:43:48 -0600 Received: from elgon.mountain (/41.212.103.53) by default (Oracle Beehive Gateway v4.0) with ESMTP ; Wed, 16 Jan 2013 23:43:48 -0800 Date: Thu, 17 Jan 2013 10:44:05 +0300 From: Dan Carpenter To: Hansjoerg Lipp Cc: Tilman Schmidt , Karsten Keil , gigaset307x-common@lists.sourceforge.net, netdev@vger.kernel.org, kernel-janitors@vger.kernel.org Subject: [patch] isdn/gigaset: off by one check leading to oops Message-ID: <20130117074405.GA26270@elgon.mountain> MIME-Version: 1.0 Content-Disposition: inline User-Agent: Mutt/1.5.21 (2010-09-15) X-Source-IP: ucsinet21.oracle.com [156.151.31.93] Sender: netdev-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: netdev@vger.kernel.org If l == 12 then later we subtract 12 leaving zero. We do a zero size allocation, so "dbgline" points to the ZERO_SIZE_PTR. It leads to an oops when we set the NUL terminator: dbgline[3 * l - 1] = '\0'; Signed-off-by: Dan Carpenter --- Static analysis stuff. -- To unsubscribe from this list: send the line "unsubscribe netdev" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html diff --git a/drivers/isdn/gigaset/capi.c b/drivers/isdn/gigaset/capi.c index 68452b7..0d34325 100644 --- a/drivers/isdn/gigaset/capi.c +++ b/drivers/isdn/gigaset/capi.c @@ -239,7 +239,7 @@ static inline void dump_rawmsg(enum debuglevel level, const char *tag, return; l = CAPIMSG_LEN(data); - if (l < 12) { + if (l <= 12) { gig_dbg(level, "%s: ??? LEN=%04d", tag, l); return; }