[SCSI] qla4xxx: overflow in qla4xxx_set_chap_entry()
We should cap the size of memcpy() because it comes from the network
and can't be trusted.
Fixes: 26ffd7b45f
('[SCSI] qla4xxx: Add support to set CHAP entries')
Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
Acked-by: Vikas Chaudhary <vikas.chaudhary@qlogic.com>
Signed-off-by: James Bottomley <JBottomley@Parallels.com>
This commit is contained in:
parent
88397c279d
commit
3c60cfd739
|
@ -861,6 +861,7 @@ static int qla4xxx_set_chap_entry(struct Scsi_Host *shost, void *data, int len)
|
||||||
int type;
|
int type;
|
||||||
int rem = len;
|
int rem = len;
|
||||||
int rc = 0;
|
int rc = 0;
|
||||||
|
int size;
|
||||||
|
|
||||||
memset(&chap_rec, 0, sizeof(chap_rec));
|
memset(&chap_rec, 0, sizeof(chap_rec));
|
||||||
|
|
||||||
|
@ -875,12 +876,14 @@ static int qla4xxx_set_chap_entry(struct Scsi_Host *shost, void *data, int len)
|
||||||
chap_rec.chap_type = param_info->value[0];
|
chap_rec.chap_type = param_info->value[0];
|
||||||
break;
|
break;
|
||||||
case ISCSI_CHAP_PARAM_USERNAME:
|
case ISCSI_CHAP_PARAM_USERNAME:
|
||||||
memcpy(chap_rec.username, param_info->value,
|
size = min_t(size_t, sizeof(chap_rec.username),
|
||||||
param_info->len);
|
param_info->len);
|
||||||
|
memcpy(chap_rec.username, param_info->value, size);
|
||||||
break;
|
break;
|
||||||
case ISCSI_CHAP_PARAM_PASSWORD:
|
case ISCSI_CHAP_PARAM_PASSWORD:
|
||||||
memcpy(chap_rec.password, param_info->value,
|
size = min_t(size_t, sizeof(chap_rec.password),
|
||||||
param_info->len);
|
param_info->len);
|
||||||
|
memcpy(chap_rec.password, param_info->value, size);
|
||||||
break;
|
break;
|
||||||
case ISCSI_CHAP_PARAM_PASSWORD_LEN:
|
case ISCSI_CHAP_PARAM_PASSWORD_LEN:
|
||||||
chap_rec.password_length = param_info->value[0];
|
chap_rec.password_length = param_info->value[0];
|
||||||
|
|
Loading…
Reference in New Issue