On 07/27, Breno Leitao wrote:
> pep_getsockopt() clamps the reported length to the caller's buffer with
> min_t(), but then stores the value with put_user(val, (int __user *)
> optval), which always writes sizeof(int) bytes. A getsockopt() call with
> an optlen smaller than sizeof(int) thus reports the clamped length yet
> writes a full int, one to three bytes past the user buffer.
>
> Write the value with copy_to_user() bounded by len, so at most optlen
> bytes are copied, matching the length reported back to userspace.
>
> Fixes: 02a47617cdce ("Phonet: implement GPRS virtual interface over PEP
> socket")
> Acked-by: Rémi Denis-Courmont <[email protected]>
> Reviewed-by: Joe Damato <[email protected]>
> Signed-off-by: Breno Leitao <[email protected]>
Acked-by: Stanislav Fomichev <[email protected]>