Source-Changes-HG archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

[src/netbsd-2-0]: src/sys/compat/freebsd Pull up following revision(s) (reque...



details:   https://anonhg.NetBSD.org/src/rev/50937e3b7c86
branches:  netbsd-2-0
changeset: 564852:50937e3b7c86
user:      tron <tron%NetBSD.org@localhost>
date:      Tue Sep 13 16:37:28 2005 +0000

description:
Pull up following revision(s) (requested by christos in ticket #5846):
        sys/compat/freebsd/freebsd_misc.c: revision 1.22 via patch
Range checks are not optional. The omission of this one, allows the user
to corrupt the heap and/or crash the kernel. (Christer Oeberg)

diffstat:

 sys/compat/freebsd/freebsd_misc.c |  18 +++++++++++-------
 1 files changed, 11 insertions(+), 7 deletions(-)

diffs (40 lines):

diff -r 6b5b55d23c38 -r 50937e3b7c86 sys/compat/freebsd/freebsd_misc.c
--- a/sys/compat/freebsd/freebsd_misc.c Tue Sep 13 16:01:50 2005 +0000
+++ b/sys/compat/freebsd/freebsd_misc.c Tue Sep 13 16:37:28 2005 +0000
@@ -1,4 +1,4 @@
-/*     $NetBSD: freebsd_misc.c,v 1.20 2003/09/18 14:44:09 pooka Exp $  */
+/*     $NetBSD: freebsd_misc.c,v 1.20.2.1 2005/09/13 16:37:28 tron Exp $       */
 
 /*
  * Copyright (c) 1995 Frank van der Linden
@@ -36,7 +36,7 @@
  */
 
 #include <sys/cdefs.h>
-__KERNEL_RCSID(0, "$NetBSD: freebsd_misc.c,v 1.20 2003/09/18 14:44:09 pooka Exp $");
+__KERNEL_RCSID(0, "$NetBSD: freebsd_misc.c,v 1.20.2.1 2005/09/13 16:37:28 tron Exp $");
 
 #if defined(_KERNEL_OPT)
 #include "opt_ntp.h"
@@ -231,12 +231,16 @@
        } */ *uap = v;
        struct proc *p = l->l_proc;
 
-       if (KTRPOINT(p, KTR_USER))
-               ktruser(p, "FreeBSD utrace", SCARG(uap, addr), SCARG(uap, len),
-                       0);
+       if (!KTRPOINT(p, KTR_USER))
+               return 0;
+
+       if (SCARG(uap, len) > KTR_USER_MAXLEN)
+               return EINVAL;
+
+       ktruser(p, "FreeBSD utrace", SCARG(uap, addr), SCARG(uap, len), 0);
        
-       return (0);
+       return 0;
 #else
-       return (ENOSYS);
+       return ENOSYS;
 #endif
 }



Home | Main Index | Thread Index | Old Index