From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S932586AbbEHSeh (ORCPT ); Fri, 8 May 2015 14:34:37 -0400 Received: from mail-wi0-f175.google.com ([209.85.212.175]:36928 "EHLO mail-wi0-f175.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S932164AbbEHSeg (ORCPT ); Fri, 8 May 2015 14:34:36 -0400 Date: Fri, 8 May 2015 21:34:32 +0300 From: Alexey Dobriyan To: akpm@linux-foundation.org Cc: linux-kernel@vger.kernel.org, linux@rasmusvillemoes.dk Subject: [PATCH 06/12] scanf: fix type range overflow Message-ID: <20150508183432.GD9182@p183.telecom.by> References: <20150508182911.GA9044@p183.telecom.by> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20150508182911.GA9044@p183.telecom.by> User-Agent: Mutt/1.5.23 (2014-03-12) Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Fun fact: uint8_t val; sscanf("256", "%hhu", &val); will return 1 and make val=0 (clearly bogus). Userspace sscanf() reports 1 parsed value, returns incorrect value but sets errno to ERANGE only for "%u" conversion and higher. %hhu and %hu are left in the cold. Having no way to report errno=ERANGE in kernel, don't report successful parsing. Patch allows to remove checks and switch to proper types in several (most?) cases: grep -e 'scanf.*%[0-9]\+[dioux]' -n -r . Such checks can be incorrect too -- checking for 3 digits with %3u for parsing uint8_t is not enough. Signed-off-by: Alexey Dobriyan --- lib/vsprintf.c | 45 ++++++++++++++++++++++++++++++++++----------- 1 file changed, 34 insertions(+), 11 deletions(-) diff --git a/lib/vsprintf.c b/lib/vsprintf.c index 6509c54..58051b4 100644 --- a/lib/vsprintf.c +++ b/lib/vsprintf.c @@ -2632,44 +2632,67 @@ int vsscanf(const char *buf, const char *fmt, va_list args) switch (qualifier) { case 'H': /* that's 'hh' in format */ - if (is_sign) + if (is_sign) { + if (val.s != (signed char)val.s) + goto out; *va_arg(args, signed char *) = val.s; - else + } else { + if (val.u != (unsigned char)val.u) + goto out; *va_arg(args, unsigned char *) = val.u; + } break; case 'h': - if (is_sign) + if (is_sign) { + if (val.s != (short)val.s) + goto out; *va_arg(args, short *) = val.s; - else + } else { + if (val.u != (unsigned short)val.u) + goto out; *va_arg(args, unsigned short *) = val.u; + } break; case 'l': - if (is_sign) + if (is_sign) { + if (val.s != (long)val.s) + goto out; *va_arg(args, long *) = val.s; - else + } else { + if (val.u != (unsigned long)val.u) + goto out; *va_arg(args, unsigned long *) = val.u; + } break; case 'L': - if (is_sign) + if (is_sign) { *va_arg(args, long long *) = val.s; - else + } else { *va_arg(args, unsigned long long *) = val.u; + } break; case 'Z': case 'z': + if (val.u != (size_t)val.u) + goto out; *va_arg(args, size_t *) = val.u; break; default: - if (is_sign) + if (is_sign) { + if (val.s != (int)val.s) + goto out; *va_arg(args, int *) = val.s; - else + } else { + if (val.u != (unsigned int)val.u) + goto out; *va_arg(args, unsigned int *) = val.u; + } break; } num++; str += len; } - +out: return num; } EXPORT_SYMBOL(vsscanf); -- 2.0.4