Re: [PATCH] thunderbolt: property: fix a buffer overflow and a missing check

2019-03-27 Thread Mukesh Ojha
On 3/25/2019 4:19 AM, Kangjie Lu wrote: First, no memory is allocated for "property->value.text"; the following strcpy will lead to a buffer overflow. Fix the commit text as there is no  overflow. only the check and resource cleanp is the fix. Second, no check is enforced for the return

Re: [PATCH] thunderbolt: property: fix a buffer overflow and a missing check

2019-03-25 Thread Mika Westerberg
On Sun, Mar 24, 2019 at 05:49:16PM -0500, Kangjie Lu wrote: > First, no memory is allocated for "property->value.text"; the > following strcpy will lead to a buffer overflow. It is actually member of union so assigning via value.txt or value.data is the same. So no buffer overflow. > Second, no

[PATCH] thunderbolt: property: fix a buffer overflow and a missing check

2019-03-24 Thread Kangjie Lu
First, no memory is allocated for "property->value.text"; the following strcpy will lead to a buffer overflow. Second, no check is enforced for the return value of kzalloc, which may lead to NULL-pointer dereference. The patch fixes the two issues. Signed-off-by: Kangjie Lu ---