From: Vincent BENAYOUN Date: Thu, 13 Nov 2014 12:47:26 +0000 (+0100) Subject: inetdevice: fixed signed integer overflow X-Git-Tag: v4.9.8~5322^2~26 X-Git-Url: http://review.tizen.org/git/?a=commitdiff_plain;h=84bc88688e3f6ef843aa8803dbcd90168bb89faf;p=platform%2Fkernel%2Flinux-rpi3.git inetdevice: fixed signed integer overflow There could be a signed overflow in the following code. The expression, (32-logmask) is comprised between 0 and 31 included. It may be equal to 31. In such a case the left shift will produce a signed integer overflow. According to the C99 Standard, this is an undefined behavior. A simple fix is to replace the signed int 1 with the unsigned int 1U. Signed-off-by: Vincent BENAYOUN Signed-off-by: David S. Miller --- diff --git a/include/linux/inetdevice.h b/include/linux/inetdevice.h index 0068708..0a21fbe 100644 --- a/include/linux/inetdevice.h +++ b/include/linux/inetdevice.h @@ -242,7 +242,7 @@ static inline void in_dev_put(struct in_device *idev) static __inline__ __be32 inet_make_mask(int logmask) { if (logmask) - return htonl(~((1<<(32-logmask))-1)); + return htonl(~((1U<<(32-logmask))-1)); return 0; }