From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([2001:4830:134:3::10]:51245) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1adWhI-0005AX-34 for qemu-devel@nongnu.org; Wed, 09 Mar 2016 00:30:12 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1adWhE-0004Ro-Tt for qemu-devel@nongnu.org; Wed, 09 Mar 2016 00:30:12 -0500 Received: from mx1.redhat.com ([209.132.183.28]:45108) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1adWhE-0004Rj-Os for qemu-devel@nongnu.org; Wed, 09 Mar 2016 00:30:08 -0500 Received: from int-mx13.intmail.prod.int.phx2.redhat.com (int-mx13.intmail.prod.int.phx2.redhat.com [10.5.11.26]) by mx1.redhat.com (Postfix) with ESMTPS id 8F5A668E0B for ; Wed, 9 Mar 2016 05:30:07 +0000 (UTC) Date: Wed, 9 Mar 2016 13:29:59 +0800 From: Peter Xu Message-ID: <20160309052959.GP2377@pxdev.xzpeter.org> References: <1457420446-25276-1-git-send-email-peterx@redhat.com> <1457420446-25276-7-git-send-email-peterx@redhat.com> <1457424644.22567.27.camel@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline In-Reply-To: <1457424644.22567.27.camel@redhat.com> Subject: Re: [Qemu-devel] [PATCH 6/8] usb: fix unbounded stack for usb_mtp_add_str List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: Gerd Hoffmann Cc: pbonzini@redhat.com, qemu-devel@nongnu.org On Tue, Mar 08, 2016 at 09:10:44AM +0100, Gerd Hoffmann wrote: > > static void usb_mtp_add_str(MTPData *data, const char *str) > > { > > +#define __WSTR_LEN (256) > > uint32_t len = strlen(str)+1; > > - wchar_t wstr[len]; > > + wchar_t wstr[__WSTR_LEN]; > > I think we should g_malloc() here. Agree. Will fix. Thanks. Peter