f2fs: fix to avoid memory leakage in f2fs_listxattr
In f2fs_listxattr, there is no boundary check before memcpy e_name to buffer. If the e_name_len is corrupted, unexpected memory contents may be returned to the buffer. Signed-off-by:Randall Huang <huangrandall@google.com> Reviewed-by:
Chao Yu <yuchao0@huawei.com> Signed-off-by:
Jaegeuk Kim <jaegeuk@kernel.org> CVE-2020-0067 (backported from commit 688078e7) [ ben_r: modified error code to older value ] Signed-off-by:
Benjamin M Romer <benjamin.romer@canonical.com> Acked-by:
Kamal Mostafa <kamal@canonical.com> Acked-by:
Kelsey Skunberg <kelsey.skunberg@canonical.com> Signed-off-by:
Kelsey Skunberg <kelsey.skunberg@canonical.com>
Showing
Please register or sign in to comment