From patchwork Mon Nov 21 11:11:04 2022 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Denis Arefev X-Patchwork-Id: 23674 Return-Path: Delivered-To: ouuuleilei@gmail.com Received: by 2002:adf:f944:0:0:0:0:0 with SMTP id q4csp1520439wrr; Mon, 21 Nov 2022 03:17:40 -0800 (PST) X-Google-Smtp-Source: AA0mqf45fujJgHLIe5vNeze6QIsb1nJBQ8N1ex6Xf1rLQ+0PEMbP0X/teMNvEIQFTpAmpmLngX1Y X-Received: by 2002:a63:4915:0:b0:470:275c:9e21 with SMTP id w21-20020a634915000000b00470275c9e21mr17307729pga.18.1669029460028; Mon, 21 Nov 2022 03:17:40 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1669029460; cv=none; d=google.com; s=arc-20160816; b=ii1OBeFUSZa6BTYjRXduQ1mrBVPi0rUmU/q8X/KID2xWpPqQ4Cucd2JTdX57C7EKoh LyKJv64y5t0vGh193cCo4fg7XIB9gMAwa2KMY0lO0/K1Le9k7o0ErEDAFaoUY6xHbrjY tbl876rh6lc5rUwQqj6JZdMK/bx0lnai04r41ZEFYBVRXKWkJnXl4o+8moLFHXkq6vHS tXOKJUVGeYB7wP0m5ky5YVtZ67l39Qg1ItVkXKLCp+PDovGOuCbJsJNTChU0cLGeMnbx WQyK6lRjuK+vZw5cE0C/z8851WB08VVhkpY+ONNzFg4vJizAu+YUqORPhIG6RtFB40ns IvWg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :message-id:date:subject:cc:to:dkim-signature:from; bh=/EgY2lXCAdAF7z2NAmaypvnrmSLjUVovTOiSsKJSrC4=; b=mzzQMq5WHyxQUjFvm4oqR+m67tpqjzrw5FPsAhNkArMUmZ0mCNElPHZm6Ql18UPnCt BV3mv3drDju/riQRuteX6EV2D5IznYxVtdUaC/uxjb9Xs3tF7vb8hZWdoZXD/YT7RbR6 cvTTgSHGj6KE1YZ87BxB6pmpwFX3zUoaonSMhZgFv6x2+vha+pCyIR2h89Cwn9vSNBfE bbbvfMExjNUsv+mZfFHl9K613A7ze7drzxGLwtnQDKK/wzMmxcReG87DBJl47mptIK1V 4qEPCgzwDFpdLBpnsFUmnDW1eOwItNPMHRjLnoBZJBzhf0gBa9PGBxCAlc6OoxX4Y15Y B+6Q== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@swemel.ru header.s=mail header.b=mrCHEs3L; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=swemel.ru Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id j21-20020a632315000000b0047060a43798si11490830pgj.461.2022.11.21.03.17.23; Mon, 21 Nov 2022 03:17:40 -0800 (PST) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=pass header.i=@swemel.ru header.s=mail header.b=mrCHEs3L; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=swemel.ru Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S231183AbiKULQm (ORCPT + 99 others); Mon, 21 Nov 2022 06:16:42 -0500 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:40066 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S230407AbiKULQU (ORCPT ); Mon, 21 Nov 2022 06:16:20 -0500 Received: from mx.swemel.ru (mx.swemel.ru [95.143.211.150]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id EF5BCC287E; Mon, 21 Nov 2022 03:11:35 -0800 (PST) From: Denis Arefev DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=swemel.ru; s=mail; t=1669029064; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding; bh=/EgY2lXCAdAF7z2NAmaypvnrmSLjUVovTOiSsKJSrC4=; b=mrCHEs3LP4MiDp0HC7rR5o7PSz4Lyw/+K937QFY9hwoliOXZZU+B77+qFTxW/KOALmNICq HZrN9qokGljlUTPg6PfBqMxjQG5KflbSyKzvcz/8oS+G0Jg6sBb7s7vydcUKH27vIEOGWj QxGwY+0unt7q36VMC06COYt5syj09wU= To: Anil Gurumurthy Cc: Sudarsana Kalluru , "James E.J. Bottomley" , "Martin K. Petersen" , linux-scsi@vger.kernel.org, linux-kernel@vger.kernel.org, trufanov@swemel.ru, vfh@swemel.ru Subject: Date: Mon, 21 Nov 2022 14:11:04 +0300 Message-Id: <20221121111104.7186-1-arefev@swemel.ru> MIME-Version: 1.0 X-Spam-Status: No, score=-2.1 required=5.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,SPF_HELO_NONE,SPF_PASS autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org X-getmail-retrieved-from-mailbox: =?utf-8?q?INBOX?= X-GMAIL-THRID: =?utf-8?q?1750104235293024344?= X-GMAIL-MSGID: =?utf-8?q?1750104235293024344?= Date: Mon, 21 Nov 2022 13:29:03 +0300 Subject: [PATCH] scsi:bfa: Eliminated buffer overflow Buffer 'cmd->adapter_hwpath' of size 32 accessed at bfad_bsg.c:101:103 can overflow, since its index 'i' can have value 32 that is out of range. Signed-off-by: Denis Arefev --- drivers/scsi/bfa/bfad_bsg.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/drivers/scsi/bfa/bfad_bsg.c b/drivers/scsi/bfa/bfad_bsg.c index be8dfbe13e90..78615ffc62ef 100644 --- a/drivers/scsi/bfa/bfad_bsg.c +++ b/drivers/scsi/bfa/bfad_bsg.c @@ -98,9 +98,9 @@ bfad_iocmd_ioc_get_info(struct bfad_s *bfad, void *cmd) /* set adapter hw path */ strcpy(iocmd->adapter_hwpath, bfad->pci_name); - for (i = 0; iocmd->adapter_hwpath[i] != ':' && i < BFA_STRING_32; i++) + for (i = 0; iocmd->adapter_hwpath[i] != ':' && i < BFA_STRING_32-2; i++) ; - for (; iocmd->adapter_hwpath[++i] != ':' && i < BFA_STRING_32; ) + for (; iocmd->adapter_hwpath[++i] != ':' && i < BFA_STRING_32-1; ) ; iocmd->adapter_hwpath[i] = '\0'; iocmd->status = BFA_STATUS_OK;