[PATCH] disk: ubi: use a format string when copying the volume name

Daniel Golle <[email protected]>
Newsgroups gmane.comp.boot-loaders.u-boot.general,gmane.comp.boot-loaders.u-boot
Message-ID <[email protected]>
part_get_info_ubi() passes the UBI volume name straight to snprintf() as
its format argument:

	snprintf(info->name, PART_NAME_LEN, vol->name);

A volume name that contains a '%' is then interpreted as a printf
conversion specifier, yielding a wrong partition name or reading
unintended variadic arguments; a '%n' would be undefined behaviour.
Volume names are user-defined and boot methods select images by volume
name, so copy the name through a "%s" format instead.

Fixes: aa5b67ce2262 ("disk: support UBI partitions")
Signed-off-by: Daniel Golle <[email protected]>
---
 drivers/mtd/ubi/part.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/mtd/ubi/part.c b/drivers/mtd/ubi/part.c
index 6c017eb7299..aff0b109b70 100644
--- a/drivers/mtd/ubi/part.c
+++ b/drivers/mtd/ubi/part.c
@@ -49,7 +49,7 @@ static int __maybe_unused part_get_info_ubi(struct blk_desc *dev_desc, int part_
 	if (!vol)
 		return -ENOENT;
 
-	snprintf(info->name, PART_NAME_LEN, vol->name);
+	snprintf(info->name, PART_NAME_LEN, "%s", vol->name);
 
 	info->start = 0;
 	info->size = (unsigned long)vol->used_bytes / dev_desc->blksz;

base-commit: ece349ade2973e220f524ce59e59711cc919263f
-- 
2.55.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.