• Dan Carpenter's avatar
    sata_sil24: memset() overflow · 14e45c15
    Dan Carpenter authored
    cb->atapi.cdb is an array of 16 u8 elements.  The call too memset()
    would set the first part of the sge array to zero as well.  It's not
    a packed struct.
    
    This one has been around for five years.  I found it with Smatch.  I
    think the reason no one has seen it before is because we normally call
    sil24_fill_sg() and that overwrites sge with proper information?
    Signed-off-by: default avatarDan Carpenter <error27@gmail.com>
    Signed-off-by: default avatarJeff Garzik <jgarzik@redhat.com>
    14e45c15
sata_sil24.c 37.9 KB