aboutsummaryrefslogtreecommitdiffstats
path: root/meta/recipes-devtools/file/file/CVE-2019-8904.patch
blob: 5c3d6f73a4cdbbf27a1b2f1389cacb9a0f48b2a4 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
From 94b7501f48e134e77716e7ebefc73d6bbe72ba55 Mon Sep 17 00:00:00 2001
From: Christos Zoulas <christos@zoulas.com>
Date: Mon, 18 Feb 2019 17:30:41 +0000
Subject: [PATCH] PR/62: spinpx: Avoid non-nul-terminated string read.

Upstream-Status: Backport
CVE: CVE-2019-8904
Affects < 5.36
[Fixup for thud context]
Signed-off-by: Armin Kuster <akuster@mvista.com>

---
 src/readelf.c | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

Index: git/src/readelf.c
===================================================================
--- git.orig/src/readelf.c
+++ git/src/readelf.c
@@ -558,8 +558,8 @@ do_bid_note(struct magic_set *ms, unsign
 	}
 	if (namesz == 4 && strcmp((char *)&nbuf[noff], "Go") == 0 &&
 	    type == NT_GO_BUILD_ID && descsz < 128) {
-		if (file_printf(ms, ", Go BuildID=%s",
-		    (char *)&nbuf[doff]) == -1)
+		if (file_printf(ms, ", Go BuildID=%.*s",
+		    CAST(int, descsz), CAST(char *, &nbuf[doff])) == -1)
 			return 1;
 		return 1;
 	}