From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1752810AbbEBAvX (ORCPT ); Fri, 1 May 2015 20:51:23 -0400 Received: from mail-wg0-f47.google.com ([74.125.82.47]:36317 "EHLO mail-wg0-f47.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1752417AbbEBAvU (ORCPT ); Fri, 1 May 2015 20:51:20 -0400 Date: Sat, 2 May 2015 03:51:16 +0300 From: Alexey Dobriyan To: akpm@linux-foundation.org Cc: linux-kernel@vger.kernel.org Subject: [PATCH 04/10] sscanf: fix overflow Message-ID: <20150502005116.GD21655@p183.telecom.by> References: <20150502004714.GA21655@p183.telecom.by> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20150502004714.GA21655@p183.telecom.by> User-Agent: Mutt/1.5.23 (2014-03-12) Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Fun fact: uint8_t val; sscanf("256", "%hhu", &val); will return 1 (as it should), and make val=0 (as it should not). Apart from correctness, patch allows to remove checks and switch to proper types in several (most?) cases: grep -e 'scanf.*%[0-9]\+[dioux]' -n -r . Such checks can be incorrect too, checking for 3 digits with %3u for parsing uint8_t is not enough. Signed-off-by: Alexey Dobriyan --- lib/vsprintf.c | 45 ++++++++++++++++++++++++++++++++++----------- 1 file changed, 34 insertions(+), 11 deletions(-) --- a/lib/vsprintf.c +++ b/lib/vsprintf.c @@ -2632,44 +2632,67 @@ int vsscanf(const char *buf, const char *fmt, va_list args) switch (qualifier) { case 'H': /* that's 'hh' in format */ - if (is_sign) + if (is_sign) { + if (val.s != (signed char)val.s) + goto out; *va_arg(args, signed char *) = val.s; - else + } else { + if (val.u != (unsigned char)val.u) + goto out; *va_arg(args, unsigned char *) = val.u; + } break; case 'h': - if (is_sign) + if (is_sign) { + if (val.s != (short)val.s) + goto out; *va_arg(args, short *) = val.s; - else + } else { + if (val.u != (unsigned short)val.u) + goto out; *va_arg(args, unsigned short *) = val.u; + } break; case 'l': - if (is_sign) + if (is_sign) { + if (val.s != (long)val.s) + goto out; *va_arg(args, long *) = val.s; - else + } else { + if (val.u != (unsigned long)val.u) + goto out; *va_arg(args, unsigned long *) = val.u; + } break; case 'L': - if (is_sign) + if (is_sign) { *va_arg(args, long long *) = val.s; - else + } else { *va_arg(args, unsigned long long *) = val.u; + } break; case 'Z': case 'z': + if (val.u != (size_t)val.u) + goto out; *va_arg(args, size_t *) = val.u; break; default: - if (is_sign) + if (is_sign) { + if (val.s != (int)val.s) + goto out; *va_arg(args, int *) = val.s; - else + } else { + if (val.u != (unsigned int)val.u) + goto out; *va_arg(args, unsigned int *) = val.u; + } break; } num++; str += len; } - +out: return num; } EXPORT_SYMBOL(vsscanf);