All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH] fs/orangefs: use snprintf() instead of sprintf()
@ 2025-06-08 16:35 Amir Mohammad Jahangirzad
  2025-06-22 18:39 ` Amir Mohammad Jahangirzad
  0 siblings, 1 reply; 6+ messages in thread
From: Amir Mohammad Jahangirzad @ 2025-06-08 16:35 UTC (permalink / raw)
  To: hubcap; +Cc: martin, devel, linux-kernel, Amir Mohammad Jahangirzad

sprintf() is discouraged for use with bounded destination buffers
as it does not prevent buffer overflows when the formatted output
exceeds the destination buffer size. snprintf() is a safer
alternative as it limits the number of bytes written and ensures
NUL-termination.

Replace sprintf() with snprintf() for copying the debug string
into a temporary buffer, using ORANGEFS_MAX_DEBUG_STRING_LEN as
the maximum size to ensure safe formatting and prevent memory
corruption in edge cases.


Signed-off-by: Amir Mohammad Jahangirzad <a.jahangirzad@gmail.com>
---
 fs/orangefs/orangefs-debugfs.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/fs/orangefs/orangefs-debugfs.c b/fs/orangefs/orangefs-debugfs.c
index f7095c91660c..e1613e0847e8 100644
--- a/fs/orangefs/orangefs-debugfs.c
+++ b/fs/orangefs/orangefs-debugfs.c
@@ -396,7 +396,7 @@ static ssize_t orangefs_debug_read(struct file *file,
 		goto out;
 
 	mutex_lock(&orangefs_debug_lock);
-	sprintf_ret = sprintf(buf, "%s", (char *)file->private_data);
+	sprintf_ret = snprintf(buf, ORANGEFS_MAX_DEBUG_STRING_LEN, "%s", (char *)file->private_data);
 	mutex_unlock(&orangefs_debug_lock);
 
 	read_ret = simple_read_from_buffer(ubuf, count, ppos, buf, sprintf_ret);
-- 
2.43.0


^ permalink raw reply related	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2025-06-30 17:18 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2025-06-08 16:35 [PATCH] fs/orangefs: use snprintf() instead of sprintf() Amir Mohammad Jahangirzad
2025-06-22 18:39 ` Amir Mohammad Jahangirzad
2025-06-22 18:48   ` Al Viro
2025-06-22 20:09     ` Amir Mohammad Jahangirzad
2025-06-23 17:02       ` Mike Marshall
2025-06-30 17:18         ` Mike Marshall

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.