Message ID | 20240111190658.153488-5-theflamefire89@gmail.com (mailing list archive) |
---|---|
State | New |
Headers | show |
Series | Bluetooth: hci_sock: Fix possible OOB write in create_monitor_event | expand |
Hi!
> From: Kees Cook <keescook@chromium.org>
commit cb3871b1cd135a6662b732fbc6b3db4afcdb4a64 upstream.
..afaict.
Best regards,
Pavel
diff --git a/net/bluetooth/hci_sock.c b/net/bluetooth/hci_sock.c index 48fcbbde9d3f0..dbbd69bf43191 100644 --- a/net/bluetooth/hci_sock.c +++ b/net/bluetooth/hci_sock.c @@ -333,7 +333,8 @@ static struct sk_buff *create_monitor_event(struct hci_dev *hdev, int event) ni->type = hdev->dev_type; ni->bus = hdev->bus; bacpy(&ni->bdaddr, &hdev->bdaddr); - memcpy(ni->name, hdev->name, strlen(hdev->name)); + memcpy_and_pad(ni->name, sizeof(ni->name), hdev->name, + strnlen(hdev->name, sizeof(ni->name)), '\0'); opcode = cpu_to_le16(HCI_MON_NEW_INDEX); break;