diff options
| author | Vasily Averin <[email protected]> | 2016-01-14 10:41:14 +0000 |
|---|---|---|
| committer | Steve French <[email protected]> | 2016-01-14 20:45:49 +0000 |
| commit | 01b9b0b28626db4a47d7f48744d70abca9914ef1 (patch) | |
| tree | fd31f5cc68e6b880be1315249de944ad8ffcd023 /drivers/acpi/cppc_acpi.c | |
| parent | cifs: fix race between call_async() and reconnect() (diff) | |
| download | kernel-01b9b0b28626db4a47d7f48744d70abca9914ef1.tar.gz kernel-01b9b0b28626db4a47d7f48744d70abca9914ef1.zip | |
cifs_dbg() outputs an uninitialized buffer in cifs_readdir()
In some cases tmp_bug can be not filled in cifs_filldir and stay uninitialized,
therefore its printk with "%s" modifier can leak content of kernelspace memory.
If old content of this buffer does not contain '\0' access bejond end of
allocated object can crash the host.
Signed-off-by: Vasily Averin <[email protected]>
Signed-off-by: Steve French <[email protected]>
CC: Stable <[email protected]>
Diffstat (limited to 'drivers/acpi/cppc_acpi.c')
0 files changed, 0 insertions, 0 deletions
