aboutsummaryrefslogtreecommitdiffstats
path: root/fs/nfs
diff options
context:
space:
mode:
authorDan Carpenter <dan.carpenter@oracle.com>2012-06-12 10:37:08 +0300
committerBen Hutchings <ben@decadent.org.uk>2013-09-10 01:57:10 +0100
commit70bea7f2c038f04b5bc2e84f12615f79ed394d13 (patch)
treef8a885a389d29aa7178f2979768f61d84b0930ad /fs/nfs
parent433b06a8f4b04e560c3ad8e13bf60b1fa6186341 (diff)
downloadkernel_samsung_smdk4412-70bea7f2c038f04b5bc2e84f12615f79ed394d13.zip
kernel_samsung_smdk4412-70bea7f2c038f04b5bc2e84f12615f79ed394d13.tar.gz
kernel_samsung_smdk4412-70bea7f2c038f04b5bc2e84f12615f79ed394d13.tar.bz2
NFSv4.1: integer overflow in decode_cb_sequence_args()
commit 0439f31c35d1da0b28988b308ea455e38e6a350d upstream. This seems like it could overflow on 32 bits. Use kmalloc_array() which has overflow protection built in. Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com> Signed-off-by: Trond Myklebust <Trond.Myklebust@netapp.com> Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
Diffstat (limited to 'fs/nfs')
-rw-r--r--fs/nfs/callback_xdr.c6
1 files changed, 3 insertions, 3 deletions
diff --git a/fs/nfs/callback_xdr.c b/fs/nfs/callback_xdr.c
index 168cb93..3fde055 100644
--- a/fs/nfs/callback_xdr.c
+++ b/fs/nfs/callback_xdr.c
@@ -451,9 +451,9 @@ static __be32 decode_cb_sequence_args(struct svc_rqst *rqstp,
args->csa_nrclists = ntohl(*p++);
args->csa_rclists = NULL;
if (args->csa_nrclists) {
- args->csa_rclists = kmalloc(args->csa_nrclists *
- sizeof(*args->csa_rclists),
- GFP_KERNEL);
+ args->csa_rclists = kmalloc_array(args->csa_nrclists,
+ sizeof(*args->csa_rclists),
+ GFP_KERNEL);
if (unlikely(args->csa_rclists == NULL))
goto out;