projects
/
platform
/
adaptation
/
renesas_rcar
/
renesas_kernel.git
/ blobdiff
commit
grep
author
committer
pickaxe
?
search:
re
summary
|
shortlog
|
log
|
commit
|
commitdiff
|
tree
raw
|
inline
| side by side
aacraid: prevent invalid pointer dereference
[platform/adaptation/renesas_rcar/renesas_kernel.git]
/
drivers
/
scsi
/
aacraid
/
commctrl.c
diff --git
a/drivers/scsi/aacraid/commctrl.c
b/drivers/scsi/aacraid/commctrl.c
index
d85ac1a
..
fbcd48d
100644
(file)
--- a/
drivers/scsi/aacraid/commctrl.c
+++ b/
drivers/scsi/aacraid/commctrl.c
@@
-511,7
+511,8
@@
static int aac_send_raw_srb(struct aac_dev* dev, void __user * arg)
goto cleanup;
}
goto cleanup;
}
- if (fibsize > (dev->max_fib_size - sizeof(struct aac_fibhdr))) {
+ if ((fibsize < (sizeof(struct user_aac_srb) - sizeof(struct user_sgentry))) ||
+ (fibsize > (dev->max_fib_size - sizeof(struct aac_fibhdr)))) {
rcode = -EINVAL;
goto cleanup;
}
rcode = -EINVAL;
goto cleanup;
}