[LTP] [PATCH 1/3] lib: Avoid loop_info.lo_name buffer overflow
Andrea Cervesato <[email protected]> Fri, 17 Jul 2026 14:33:18 +0200
| Newsgroups | it.linux.lists.ltp |
|---|---|
| Message-ID | <[email protected]> |
From: Andrea Cervesato <[email protected]> The backing file path may be longer than the fixed-size lo_name field, so an unbounded strcpy() can overflow the loop_info structure. Copy at most the field size and rely on the preceding memset() for termination. Signed-off-by: Andrea Cervesato <[email protected]> --- lib/tst_device.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/lib/tst_device.c b/lib/tst_device.c index d3c53a1a18d2e4948ebff21d6d66c0ccd1590c6f..b5c3ccdb7be52ce600fbd7d7a83f6081df65d616 100644 --- a/lib/tst_device.c +++ b/lib/tst_device.c @@ -182,7 +182,7 @@ int tst_attach_device(const char *dev, const char *file) * LOOP_SET_FD and LOOP_SET_STATUS. */ memset(&loopinfo, 0, sizeof(loopinfo)); - strcpy(loopinfo.lo_name, file); + strncpy(loopinfo.lo_name, file, sizeof(loopinfo.lo_name) - 1); if (ioctl(dev_fd, LOOP_SET_STATUS, &loopinfo)) { close(dev_fd); -- 2.51.0 -- Mailing list info: https://lists.linux.it/listinfo/ltp