From: David Decotigny <ddecotig@gmail.com>
To: netdev@vger.kernel.org
Cc: Jeff Garzik <jgarzik@pobox.com>,
Ben Hutchings <ben@decadent.org.uk>,
David Miller <davem@redhat.com>,
Vidya Sagar Ravipati <vidya@cumulusnetworks.com>,
Joe Perches <joe@perches.com>,
David Decotigny <decot@googlers.com>
Subject: [ethtool PATCH v4 03/11] ethtool.c: fix dump_regs heap corruption
Date: Fri, 11 Mar 2016 09:58:16 -0800 [thread overview]
Message-ID: <1457719104-39188-4-git-send-email-ddecotig@gmail.com> (raw)
In-Reply-To: <1457719104-39188-1-git-send-email-ddecotig@gmail.com>
From: David Decotigny <decot@googlers.com>
The 'regs' pointer is owned by do_gregs(), but updated internally inside
dump_regs() without propagating it back to do_gregs(): later free(regs)
in do_gregs() reclaims the wrong area. This commit moves the realloc()
inside do_gregs().
Signed-off-by: David Decotigny <decot@googlers.com>
---
ethtool.c | 46 +++++++++++++++++++++++++---------------------
1 file changed, 25 insertions(+), 21 deletions(-)
diff --git a/ethtool.c b/ethtool.c
index 9f80d5f..7c2b5cb 100644
--- a/ethtool.c
+++ b/ethtool.c
@@ -994,7 +994,6 @@ void dump_hex(FILE *file, const u8 *data, int len, int offset)
}
static int dump_regs(int gregs_dump_raw, int gregs_dump_hex,
- const char *gregs_dump_file,
struct ethtool_drvinfo *info, struct ethtool_regs *regs)
{
int i;
@@ -1004,25 +1003,6 @@ static int dump_regs(int gregs_dump_raw, int gregs_dump_hex,
return 0;
}
- if (gregs_dump_file) {
- FILE *f = fopen(gregs_dump_file, "r");
- struct stat st;
- size_t nread;
-
- if (!f || fstat(fileno(f), &st) < 0) {
- fprintf(stderr, "Can't open '%s': %s\n",
- gregs_dump_file, strerror(errno));
- return -1;
- }
-
- regs = realloc(regs, sizeof(*regs) + st.st_size);
- regs->len = st.st_size;
- nread = fread(regs->data, regs->len, 1, f);
- fclose(f);
- if (nread != 1)
- return -1;
- }
-
if (!gregs_dump_hex)
for (i = 0; i < ARRAY_SIZE(driver_list); i++)
if (!strncmp(driver_list[i].name, info->driver,
@@ -2711,7 +2691,31 @@ static int do_gregs(struct cmd_context *ctx)
free(regs);
return 74;
}
- if (dump_regs(gregs_dump_raw, gregs_dump_hex, gregs_dump_file,
+
+ if (!gregs_dump_raw && gregs_dump_file != NULL) {
+ /* overwrite reg values from file dump */
+ FILE *f = fopen(gregs_dump_file, "r");
+ struct stat st;
+ size_t nread;
+
+ if (!f || fstat(fileno(f), &st) < 0) {
+ fprintf(stderr, "Can't open '%s': %s\n",
+ gregs_dump_file, strerror(errno));
+ free(regs);
+ return 75;
+ }
+
+ regs = realloc(regs, sizeof(*regs) + st.st_size);
+ regs->len = st.st_size;
+ nread = fread(regs->data, regs->len, 1, f);
+ fclose(f);
+ if (nread != 1) {
+ free(regs);
+ return 75;
+ }
+ }
+
+ if (dump_regs(gregs_dump_raw, gregs_dump_hex,
&drvinfo, regs) < 0) {
fprintf(stderr, "Cannot dump registers\n");
free(regs);
--
2.7.0.rc3.207.g0ac5344
next prev parent reply other threads:[~2016-03-11 17:58 UTC|newest]
Thread overview: 22+ messages / expand[flat|nested] mbox.gz Atom feed top
2016-03-11 17:58 [ethtool PATCH v4 00/11] add support for new ETHTOOL_xLINKSETTINGS ioctls David Decotigny
2016-03-11 17:58 ` [ethtool PATCH v4 01/11] internal.h: change to new sane kernel headers on 64-bit archs David Decotigny
2016-03-11 17:58 ` [ethtool PATCH v4 02/11] ethtool.c: don't ignore fread() return value David Decotigny
2016-03-11 17:58 ` David Decotigny [this message]
2016-03-11 17:58 ` [ethtool PATCH v4 04/11] ethtool.c: do_seeprom checks for params & stdin sanity David Decotigny
2016-03-11 17:58 ` [ethtool PATCH v4 05/11] marvell.c: fix strict alias warnings David Decotigny
2016-03-11 17:58 ` [ethtool PATCH v4 06/11] test-common.c: fix test_realloc(NULL, ...) David Decotigny
2016-03-11 17:58 ` [ethtool PATCH v4 07/11] test-features.c: add braces around array initialization David Decotigny
2016-03-11 17:58 ` [ethtool PATCH v4 08/11] kernel-copy.h: import kernel.h from net-next and use it David Decotigny
2016-03-11 17:58 ` [ethtool PATCH v4 09/11] ethtool-copy.h: sync with net-next David Decotigny
2016-03-11 17:58 ` [ethtool PATCH v4 10/11] ethtool.c: add support for ETHTOOL_xLINKSETTINGS ioctls David Decotigny
2016-03-14 1:32 ` Ben Hutchings
2016-03-14 16:43 ` David Laight
2016-03-15 23:42 ` David Decotigny
2016-03-15 23:47 ` David Decotigny
2016-03-11 17:58 ` [ethtool PATCH v4 11/11] ethtool.c: support absence of v4 sockets David Decotigny
2016-03-13 17:24 ` Ben Hutchings
2016-03-15 23:19 ` David Decotigny
2016-03-15 23:23 ` Ben Hutchings
2016-03-13 17:30 ` [ethtool PATCH v4 00/11] add support for new ETHTOOL_xLINKSETTINGS ioctls Ben Hutchings
2016-03-14 0:27 ` Ben Hutchings
-- strict thread matches above, loose matches on Subject: below --
2016-03-08 3:34 David Decotigny
2016-03-08 3:34 ` [ethtool PATCH v4 03/11] ethtool.c: fix dump_regs heap corruption David Decotigny
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1457719104-39188-4-git-send-email-ddecotig@gmail.com \
--to=ddecotig@gmail.com \
--cc=ben@decadent.org.uk \
--cc=davem@redhat.com \
--cc=decot@googlers.com \
--cc=jgarzik@pobox.com \
--cc=joe@perches.com \
--cc=netdev@vger.kernel.org \
--cc=vidya@cumulusnetworks.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).