Source-Changes-HG archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

[src/trunk]: src/sys/kern kobj(9): Avoid arithmetic overflow in overflow dete...



details:   https://anonhg.NetBSD.org/src/rev/7100a8516680
branches:  trunk
changeset: 371872:7100a8516680
user:      riastradh <riastradh%NetBSD.org@localhost>
date:      Sat Oct 15 15:23:24 2022 +0000

description:
kobj(9): Avoid arithmetic overflow in overflow detection.

diffstat:

 sys/kern/subr_kobj.c |  7 ++++---
 1 files changed, 4 insertions(+), 3 deletions(-)

diffs (28 lines):

diff -r 11cba91bbe66 -r 7100a8516680 sys/kern/subr_kobj.c
--- a/sys/kern/subr_kobj.c      Sat Oct 15 15:22:27 2022 +0000
+++ b/sys/kern/subr_kobj.c      Sat Oct 15 15:23:24 2022 +0000
@@ -1,4 +1,4 @@
-/*     $NetBSD: subr_kobj.c,v 1.70 2022/10/15 15:22:27 riastradh Exp $ */
+/*     $NetBSD: subr_kobj.c,v 1.71 2022/10/15 15:23:24 riastradh Exp $ */
 
 /*
  * Copyright (c) 2008 The NetBSD Foundation, Inc.
@@ -63,7 +63,7 @@
  */
 
 #include <sys/cdefs.h>
-__KERNEL_RCSID(0, "$NetBSD: subr_kobj.c,v 1.70 2022/10/15 15:22:27 riastradh Exp $");
+__KERNEL_RCSID(0, "$NetBSD: subr_kobj.c,v 1.71 2022/10/15 15:23:24 riastradh Exp $");
 
 #ifdef _KERNEL_OPT
 #include "opt_modular.h"
@@ -1154,7 +1154,8 @@
                    (unsigned long long)off);
                error = EINVAL;
                base = NULL;
-       } else if (ko->ko_memsize != -1 && off + size > ko->ko_memsize) {
+       } else if (ko->ko_memsize != -1 &&
+           (size > ko->ko_memsize || off > ko->ko_memsize - size)) {
                kobj_error(ko, "preloaded object short");
                error = EINVAL;
                base = NULL;



Home | Main Index | Thread Index | Old Index