diff options
| author | Dmitry Torokhov <dmitry.torokhov@gmail.com> | 2017-10-23 16:46:00 -0700 |
|---|---|---|
| committer | Gerrit - the friendly Code Review server <code-review@localhost> | 2018-05-29 01:50:46 -0700 |
| commit | 649de266e2b7c26a70ace40231d1d835a4561500 (patch) | |
| tree | c5f54ee795b6751f22c9f7e3796b68828de1eea0 /net/lapb/lapb_in.c | |
| parent | d109e62922ad25c23e44cd44ba6b1b63080099e2 (diff) | |
Input: gtco - fix potential out-of-bound access
parse_hid_report_descriptor() has a while (i < length) loop, which
only guarantees that there's at least 1 byte in the buffer, but the
loop body can read multiple bytes which causes out-of-bounds access.
Reported-by: Andrey Konovalov <andreyknvl@google.com>
Reviewed-by: Andrey Konovalov <andreyknvl@google.com>
Cc: stable@vger.kernel.org
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Change-Id: I7b57556c100d28d8f10c03ea5480224e770fb64a
Git-commit: a50829479f58416a013a4ccca791336af3c584c7
Git-repo: https://android.googlesource.com/kernel/common
Signed-off-by: Srinivasa Rao Kuppala <srkupp@codeaurora.org>
Diffstat (limited to 'net/lapb/lapb_in.c')
0 files changed, 0 insertions, 0 deletions
