From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Martin K. Petersen" Subject: Re: [patch v2] arcmsr: buffer overflow in arcmsr_iop_message_xfer() Date: Mon, 26 Sep 2016 21:08:51 -0400 Message-ID: References: <20160915134456.GA30277@mwanda> <20160923112226.rteir5ivjou64ffh@pd.tnic> Mime-Version: 1.0 Content-Type: text/plain Return-path: Received: from userp1040.oracle.com ([156.151.31.81]:26944 "EHLO userp1040.oracle.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1755488AbcI0BJl (ORCPT ); Mon, 26 Sep 2016 21:09:41 -0400 In-Reply-To: <20160923112226.rteir5ivjou64ffh@pd.tnic> (Borislav Petkov's message of "Fri, 23 Sep 2016 13:22:26 +0200") Sender: linux-scsi-owner@vger.kernel.org List-Id: linux-scsi@vger.kernel.org To: Borislav Petkov Cc: "Martin K. Petersen" , Dan Carpenter , "James E.J. Bottomley" , Ching Huang , Hannes Reinicke , Johannes Thumshirn , Tomas Henzl , linux-scsi@vger.kernel.org, security@kernel.org >>>>> "Borislav" == Borislav Petkov writes: Borislav> Yap, Tomas said the kfree was missing on the error path but Borislav> can we simplify this further by doing the user_len check first Borislav> so that the kfree() is not even needed? Applied to 4.9/scsi-queue. -- Martin K. Petersen Oracle Linux Engineering