From: Jens Axboe on 2 Apr 2010 02:50 On Tue, Mar 30 2010, wzt.wzt(a)gmail.com wrote: > elevator_get() not check the name length, if the name length > sizeof(elv), > elv will miss the '\0'. And elv buffer will be replace "-iosched" as something > like aaaaaaaaa, then call request_module() can load an not trust module. Thanks, good catch! Applied. -- Jens Axboe -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo(a)vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
|
Pages: 1 Prev: blkio: IO controller stats Next: Block: Fix block/elevator.c elevator_get() off-by-one error |