asm-generic: uaccess: add missing access_ok() check to strnlen_user()
The strnlen_user() function was missing a access_ok() check on the pointer given. We've had cases on Blackfin systems where test programs caused kernel crashes here because userspace passed up a NULL/-1 pointer and the kernel gladly attempted to run strlen() on it. Signed-off-by: Mike Frysinger <vapier@gentoo.org> Signed-off-by: Arnd Bergmann <arnd@arndb.de>
This commit is contained in:
parent
0732f87761
commit
9844813f22
@ -291,6 +291,8 @@ strncpy_from_user(char *dst, const char __user *src, long count)
|
|||||||
#ifndef strnlen_user
|
#ifndef strnlen_user
|
||||||
static inline long strnlen_user(const char __user *src, long n)
|
static inline long strnlen_user(const char __user *src, long n)
|
||||||
{
|
{
|
||||||
|
if (!access_ok(VERIFY_READ, src, 1))
|
||||||
|
return 0;
|
||||||
return strlen((void * __force)src) + 1;
|
return strlen((void * __force)src) + 1;
|
||||||
}
|
}
|
||||||
#endif
|
#endif
|
||||||
|
Loading…
Reference in New Issue
Block a user