From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Martin K. Petersen" Date: Thu, 27 Jul 2017 02:10:06 +0000 Subject: Re: [PATCH 1/2] scsi: aacraid: reading out of bounds Message-Id: List-Id: References: <20170725194955.dd4g6msevoesty4t@mwanda> In-Reply-To: <20170725194955.dd4g6msevoesty4t@mwanda> (Dan Carpenter's message of "Tue, 25 Jul 2017 22:49:55 +0300") MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit To: Dan Carpenter Cc: Adaptec OEM Raid Solutions , "James E.J. Bottomley" , "Martin K. Petersen" , linux-scsi@vger.kernel.org, kernel-janitors@vger.kernel.org Dan, > "qd.id" comes directly from the copy_from_user() on the line before so > we should verify that it's within bounds. Applied to 4.13/scsi-fixes. Thanks! -- Martin K. Petersen Oracle Linux Engineering