From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([2001:4830:134:3::10]:47406) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1WIYPF-00071B-Mc for qemu-devel@nongnu.org; Wed, 26 Feb 2014 01:55:58 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1WIYP6-0003l1-Oo for qemu-devel@nongnu.org; Wed, 26 Feb 2014 01:55:49 -0500 Received: from e28smtp03.in.ibm.com ([122.248.162.3]:54902) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1WIYP5-0003kh-VN for qemu-devel@nongnu.org; Wed, 26 Feb 2014 01:55:40 -0500 Received: from /spool/local by e28smtp03.in.ibm.com with IBM ESMTP SMTP Gateway: Authorized Use Only! Violators will be prosecuted for from ; Wed, 26 Feb 2014 12:25:36 +0530 Received: from d28relay03.in.ibm.com (d28relay03.in.ibm.com [9.184.220.60]) by d28dlp01.in.ibm.com (Postfix) with ESMTP id C38E7E0045 for ; Wed, 26 Feb 2014 12:29:06 +0530 (IST) Received: from d28av02.in.ibm.com (d28av02.in.ibm.com [9.184.220.64]) by d28relay03.in.ibm.com (8.13.8/8.13.8/NCO v10.0) with ESMTP id s1Q6tIsg60817562 for ; Wed, 26 Feb 2014 12:25:18 +0530 Received: from d28av02.in.ibm.com (localhost [127.0.0.1]) by d28av02.in.ibm.com (8.14.4/8.14.4/NCO v10.0 AVout) with ESMTP id s1Q6tXWR023091 for ; Wed, 26 Feb 2014 12:25:33 +0530 From: "Aneesh Kumar K.V" In-Reply-To: <1393000989-8502-1-git-send-email-armbru@redhat.com> References: <1393000989-8502-1-git-send-email-armbru@redhat.com> Date: Wed, 26 Feb 2014 12:25:32 +0530 Message-ID: <87sir6fjmj.fsf@linux.vnet.ibm.com> MIME-Version: 1.0 Content-Type: text/plain Subject: Re: [Qemu-devel] [PATCH] fsdev: Fix overrun after readlink() fills buffer completely List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: Markus Armbruster , qemu-devel@nongnu.org Markus Armbruster writes: > readlink() returns the number of bytes written to the buffer, and it > doesn't write a terminating null byte. do_readlink() writes it > itself. Overruns the buffer when readlink() filled it completely. > > Fix by reserving space for the null byte when calling readlink(), like > we do elsewhere. > > Signed-off-by: Markus Armbruster applied. > --- > fsdev/virtfs-proxy-helper.c | 2 +- > 1 file changed, 1 insertion(+), 1 deletion(-) > > diff --git a/fsdev/virtfs-proxy-helper.c b/fsdev/virtfs-proxy-helper.c > index 713a7b2..bfecb87 100644 > --- a/fsdev/virtfs-proxy-helper.c > +++ b/fsdev/virtfs-proxy-helper.c > @@ -595,7 +595,7 @@ static int do_readlink(struct iovec *iovec, struct iovec *out_iovec) > } > buffer = g_malloc(size); > v9fs_string_init(&target); > - retval = readlink(path.data, buffer, size); > + retval = readlink(path.data, buffer, size - 1); > if (retval > 0) { > buffer[retval] = '\0'; > v9fs_string_sprintf(&target, "%s", buffer); > -- > 1.8.1.4