From: David Decotigny <ddecotig@gmail.com>
To: netdev@vger.kernel.org
Cc: Jeff Garzik <jgarzik@pobox.com>,
Ben Hutchings <ben@decadent.org.uk>,
David Miller <davem@redhat.com>,
Vidya Sagar Ravipati <vidya@cumulusnetworks.com>,
David Decotigny <decot@googlers.com>
Subject: [ethtool PATCH v2 03/12] ethtool.c: fix dump_regs heap corruption
Date: Thu, 3 Mar 2016 20:23:16 -0800 [thread overview]
Message-ID: <1457065405-19049-4-git-send-email-ddecotig@gmail.com> (raw)
In-Reply-To: <1457065405-19049-1-git-send-email-ddecotig@gmail.com>
From: David Decotigny <decot@googlers.com>
The 'regs' pointer is owned by do_gregs(), but updated internally inside
dump_regs() without propagating it back to do_gregs(): later free(regs)
in do_gregs() reclaims the wrong area. This commit moves the realloc()
inside do_gregs().
Signed-off-by: David Decotigny <decot@googlers.com>
---
ethtool.c | 46 +++++++++++++++++++++++++---------------------
1 file changed, 25 insertions(+), 21 deletions(-)
diff --git a/ethtool.c b/ethtool.c
index 8a93dd1..c64b962 100644
--- a/ethtool.c
+++ b/ethtool.c
@@ -994,7 +994,6 @@ void dump_hex(FILE *file, const u8 *data, int len, int offset)
}
static int dump_regs(int gregs_dump_raw, int gregs_dump_hex,
- const char *gregs_dump_file,
struct ethtool_drvinfo *info, struct ethtool_regs *regs)
{
int i;
@@ -1004,25 +1003,6 @@ static int dump_regs(int gregs_dump_raw, int gregs_dump_hex,
return 0;
}
- if (gregs_dump_file) {
- FILE *f = fopen(gregs_dump_file, "r");
- struct stat st;
- size_t nread;
-
- if (!f || fstat(fileno(f), &st) < 0) {
- fprintf(stderr, "Can't open '%s': %s\n",
- gregs_dump_file, strerror(errno));
- return -1;
- }
-
- regs = realloc(regs, sizeof(*regs) + st.st_size);
- regs->len = st.st_size;
- nread = fread(regs->data, regs->len, 1, f);
- fclose(f);
- if (1 != nread)
- return -1;
- }
-
if (!gregs_dump_hex)
for (i = 0; i < ARRAY_SIZE(driver_list); i++)
if (!strncmp(driver_list[i].name, info->driver,
@@ -2711,7 +2691,31 @@ static int do_gregs(struct cmd_context *ctx)
free(regs);
return 74;
}
- if (dump_regs(gregs_dump_raw, gregs_dump_hex, gregs_dump_file,
+
+ if ((!gregs_dump_raw) && (NULL != gregs_dump_file)) {
+ /* overwrite reg values from file dump */
+ FILE *f = fopen(gregs_dump_file, "r");
+ struct stat st;
+ size_t nread;
+
+ if (!f || fstat(fileno(f), &st) < 0) {
+ fprintf(stderr, "Can't open '%s': %s\n",
+ gregs_dump_file, strerror(errno));
+ free(regs);
+ return 75;
+ }
+
+ regs = realloc(regs, sizeof(*regs) + st.st_size);
+ regs->len = st.st_size;
+ nread = fread(regs->data, regs->len, 1, f);
+ fclose(f);
+ if (1 != nread) {
+ free(regs);
+ return 75;
+ }
+ }
+
+ if (dump_regs(gregs_dump_raw, gregs_dump_hex,
&drvinfo, regs) < 0) {
fprintf(stderr, "Cannot dump registers\n");
free(regs);
--
2.7.0.rc3.207.g0ac5344
next prev parent reply other threads:[~2016-03-04 4:23 UTC|newest]
Thread overview: 18+ messages / expand[flat|nested] mbox.gz Atom feed top
2016-03-04 4:23 [ethtool PATCH v2 00/12] add support for new ETHTOOL_xLINKSETTINGS ioctls David Decotigny
2016-03-04 4:23 ` [ethtool PATCH v2 01/12] internal.h: change to new sane powerpc64 kernel headers David Decotigny
2016-03-04 13:31 ` Maciej Żenczykowski
2016-03-04 4:23 ` [ethtool PATCH v2 02/12] ethtool.c: don't ignore fread() return value David Decotigny
2016-03-04 4:23 ` David Decotigny [this message]
2016-03-04 4:23 ` [ethtool PATCH v2 04/12] ethtool.c: do_seeprom checks for params & stdin sanity David Decotigny
2016-03-04 4:23 ` [ethtool PATCH v2 05/12] marvell.c: fix strict alias warnings David Decotigny
2016-03-04 13:31 ` Maciej Żenczykowski
2016-03-04 4:23 ` [ethtool PATCH v2 06/12] test-common.c: fix test_realloc(NULL, ...) David Decotigny
2016-03-04 13:32 ` Maciej Żenczykowski
2016-03-04 4:23 ` [ethtool PATCH v2 07/12] test-features.c: add braces around array initialization David Decotigny
2016-03-04 13:31 ` Maciej Żenczykowski
2016-03-04 4:23 ` [ethtool PATCH v2 08/12] ethtool-copy.h: sync with net-next David Decotigny
2016-03-04 4:23 ` [ethtool PATCH v2 09/12] internal.h: fix build for latest ethtool-copy.h David Decotigny
2016-03-04 4:23 ` [ethtool PATCH v2 10/12] internal.h: TRUE/FALSE macros David Decotigny
2016-03-04 4:35 ` Joe Perches
2016-03-04 4:23 ` [ethtool PATCH v2 11/12] ethtool.c: add support for ETHTOOL_xLINKSETTINGS ioctls David Decotigny
2016-03-04 4:23 ` [ethtool PATCH v2 12/12] ethtool.c: use v6 socket when v4 is not available David Decotigny
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1457065405-19049-4-git-send-email-ddecotig@gmail.com \
--to=ddecotig@gmail.com \
--cc=ben@decadent.org.uk \
--cc=davem@redhat.com \
--cc=decot@googlers.com \
--cc=jgarzik@pobox.com \
--cc=netdev@vger.kernel.org \
--cc=vidya@cumulusnetworks.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).