On 07/27, Breno Leitao wrote:
> pep_getsockopt() clamps the reported length to the caller's buffer with
> min_t(), but then stores the value with put_user(val, (int __user *)
> optval), which always writes sizeof(int) bytes. A getsockopt() call with
> an optlen smaller than sizeof(int) thus reports the clamped length yet
> writes a full int, one to three bytes past the user buffer.
> 
> Write the value with copy_to_user() bounded by len, so at most optlen
> bytes are copied, matching the length reported back to userspace.
> 
> Fixes: 02a47617cdce ("Phonet: implement GPRS virtual interface over PEP 
> socket")
> Acked-by: RĂ©mi Denis-Courmont <[email protected]>
> Reviewed-by: Joe Damato <[email protected]>
> Signed-off-by: Breno Leitao <[email protected]>

Acked-by: Stanislav Fomichev <[email protected]>

Reply via email to