Re: [ 092/180] udf: Avoid run away loop when partition tablelength is corrupted

From: Ben Hutchings
Date: Thu Oct 04 2012 - 17:48:28 EST


On Tue, Oct 02, 2012 at 12:53:29AM +0200, Willy Tarreau wrote:
> 2.6.32-longterm review patch. If anyone has any objections, please let me know.
>
> ------------------
>
> From: Jan Kara <jack@xxxxxxx>
>
> commit adee11b2085bee90bd8f4f52123ffb07882d6256 upstream.
>
> Check provided length of partition table so that (possibly maliciously)
> corrupted partition table cannot cause accessing data beyond current buffer.
[...]

This is not quite paranoid enough; please add commit
57b9655d01ef057a523e810d29c37ac09b80eead after this.

Ben.

--
Ben Hutchings
We get into the habit of living before acquiring the habit of thinking.
- Albert Camus
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/