Re: [PATCH] Buffer overflow in devclass_add_device()

Attilio Rao <[email protected]> Fri, 6 Nov 2009 17:22:36 +0100
Newsgroups gmane.os.freebsd.devel.new-bus
Message-ID <[email protected]>
2009/11/6 M. Warner Losh <[email protected]>:
> In message: <[email protected]>
>            Attilio Rao <[email protected]> writes:
> : A buffer overflow is possible in devclass_add_device().
> : More specifically, the dev nameunit construction is based on the
> : assumption that the unit linked with the device is invariant but that
> : can change when calling devclass_alloc_unit() (because -1 is passed
> : or, more simply, because the unit choosen is beyond the table limits).
> : This results in a buffer overflow if the bug is too short on the
> : second snprintf().
> : This patch should fix it:
> : http://www.freebsd.org/~attilio/Sandvine/STABLE_8/subr_bus/subr_bus.diff
> :
> : aiming for the max possible number of digits necessary.
> : This bug has been found by Sandvine Incorporated.
> : Please reivew.
>
> I don't see a problem with it, except you'd want -INT_MAX to be
> paranoid, since it is one character longer (or just add 1) :)

I don't think that unit number can grow negative, can they?

Thanks,
Attilio


-- 
Peace can only be achieved by understanding - A. Einstein
_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-new-bus
To unsubscribe, send any mail to "[email protected]"