commit | 43629f8f5ea32a998d06d1bb41eefa0e821ff573 | [log] [tgz] |
---|---|---|
author | Vasiliy Kulikov <segoon@openwall.com> | Mon Feb 14 13:54:31 2011 +0300 |
committer | Gustavo F. Padovan <padovan@profusion.mobi> | Mon Feb 14 12:51:33 2011 -0200 |
tree | 6cc475d80311abf2b06e2b8a2cfd96043192decd | |
parent | d9f51b51db2064c9049bf7924318fd8c6ed852cb [diff] |
Bluetooth: bnep: fix buffer overflow Struct ca is copied from userspace. It is not checked whether the "device" field is NULL terminated. This potentially leads to BUG() inside of alloc_netdev_mqs() and/or information leak by creating a device with a name made of contents of kernel stack. Signed-off-by: Vasiliy Kulikov <segoon@openwall.com> Signed-off-by: Gustavo F. Padovan <padovan@profusion.mobi>