From: Laurent Vivier <laurent@vivier.eu>
To: qemu-devel@nongnu.org
Cc: "Riku Voipio" <riku.voipio@iki.fi>,
"Laurent Vivier" <laurent@vivier.eu>,
"Mark Cave-Ayland" <mark.cave-ayland@ilande.co.uk>,
"Artyom Tarasenko" <atar4qemu@gmail.com>,
"Philippe Mathieu-Daudé" <f4bug@amsat.org>
Subject: [Qemu-devel] [PULL 01/17] syscall: replace strcpy() by g_strlcpy()
Date: Mon, 4 Jun 2018 17:19:59 +0200 [thread overview]
Message-ID: <20180604152015.13359-2-laurent@vivier.eu> (raw)
In-Reply-To: <20180604152015.13359-1-laurent@vivier.eu>
From: Philippe Mathieu-Daudé <f4bug@amsat.org>
linux-user/syscall.c:9860:17: warning: Call to function 'strcpy' is insecure as it does not provide bounding of the memory buffer. Replace unbounded copy functions with analogous functions that support length arguments such as 'strlcpy'. CWE-119
strcpy (buf->machine, cpu_to_uname_machine(cpu_env));
^~~~~~
Reported-by: Clang Static Analyzer
Signed-off-by: Philippe Mathieu-Daudé <f4bug@amsat.org>
Reviewed-by: Laurent Vivier <laurent@vivier.eu>
Message-Id: <20170724182751.18261-32-f4bug@amsat.org>
Signed-off-by: Laurent Vivier <laurent@vivier.eu>
---
linux-user/syscall.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/linux-user/syscall.c b/linux-user/syscall.c
index d02c16bbc6..7b9ac3b408 100644
--- a/linux-user/syscall.c
+++ b/linux-user/syscall.c
@@ -10156,7 +10156,8 @@ abi_long do_syscall(void *cpu_env, int num, abi_long arg1,
if (!is_error(ret)) {
/* Overwrite the native machine name with whatever is being
emulated. */
- strcpy (buf->machine, cpu_to_uname_machine(cpu_env));
+ g_strlcpy(buf->machine, cpu_to_uname_machine(cpu_env),
+ sizeof(buf->machine));
/* Allow the user to override the reported release. */
if (qemu_uname_release && *qemu_uname_release) {
g_strlcpy(buf->release, qemu_uname_release,
--
2.14.3
next prev parent reply other threads:[~2018-06-04 15:20 UTC|newest]
Thread overview: 20+ messages / expand[flat|nested] mbox.gz Atom feed top
2018-06-04 15:19 [Qemu-devel] [PULL 00/17] Linux user for 3.0 patches Laurent Vivier
2018-06-04 15:19 ` Laurent Vivier [this message]
2018-06-04 15:20 ` [Qemu-devel] [PULL 02/17] linux-user: SPARC "rd %tick" can be used by user application Laurent Vivier
2018-06-04 15:20 ` [Qemu-devel] [PULL 03/17] linux-user: move generic fcntl definitions to generic/fcntl.h Laurent Vivier
2018-06-04 15:20 ` [Qemu-devel] [PULL 04/17] linux-user: move alpha fcntl definitions to alpha/target_fcntl.h Laurent Vivier
2018-06-04 15:20 ` [Qemu-devel] [PULL 05/17] linux-user: move hppa fcntl definitions to hppa/target_fcntl.h Laurent Vivier
2018-06-04 15:20 ` [Qemu-devel] [PULL 06/17] linux-user: move arm/aarch64/m68k fcntl definitions to [arm|aarch64|m68k]/target_fcntl.h Laurent Vivier
2018-06-04 15:20 ` [Qemu-devel] [PULL 07/17] linux-user: move mips/mips64 fcntl definitions to mips/target_fcntl.h Laurent Vivier
2018-06-04 15:20 ` [Qemu-devel] [PULL 08/17] linux-user: move ppc fcntl definitions to ppc/target_fcntl.h Laurent Vivier
2018-06-04 15:20 ` [Qemu-devel] [PULL 09/17] linux-user: move sparc/sparc64 fcntl definitions to sparc/target_fcntl.h Laurent Vivier
2018-06-04 15:20 ` [Qemu-devel] [PULL 10/17] linux-user: move get_sp_from_cpustate() to target_cpu.h Laurent Vivier
2018-06-04 15:20 ` [Qemu-devel] [PULL 11/17] linux-user: move generic signal definitions to generic/signal.h Laurent Vivier
2018-06-04 15:20 ` [Qemu-devel] [PULL 12/17] linux-user: move sparc signal definitions to sparc/target_signal.h Laurent Vivier
2018-06-04 15:20 ` [Qemu-devel] [PULL 13/17] linux-user: move mips signal definitions to mips/target_signal.h Laurent Vivier
2018-06-04 15:20 ` [Qemu-devel] [PULL 14/17] linux-user: move openrisc signal definitions to openrisc/target_signal.h Laurent Vivier
2018-06-04 15:20 ` [Qemu-devel] [PULL 15/17] linux-user: move alpha signal definitions to alpha/target_signal.h Laurent Vivier
2018-06-04 15:20 ` [Qemu-devel] [PULL 16/17] linux-user: move hppa signal definitions to hppa/target_signal.h Laurent Vivier
2018-06-04 15:20 ` [Qemu-devel] [PULL 17/17] linux-user: remove useless #if Laurent Vivier
2018-06-04 15:48 ` [Qemu-devel] [PULL 00/17] Linux user for 3.0 patches no-reply
2018-06-05 10:46 ` Peter Maydell
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20180604152015.13359-2-laurent@vivier.eu \
--to=laurent@vivier.eu \
--cc=atar4qemu@gmail.com \
--cc=f4bug@amsat.org \
--cc=mark.cave-ayland@ilande.co.uk \
--cc=qemu-devel@nongnu.org \
--cc=riku.voipio@iki.fi \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).