[libvirt] [PATCH v2] util: Fix stack smashing in virNetDevGetFamilyId
Jiri Denemark
jdenemar at redhat.com
Fri Sep 22 07:19:37 UTC 2017
On Thu, Sep 21, 2017 at 15:25:37 -0400, John Ferlan wrote:
>
>
> On 09/21/2017 01:57 PM, Laine Stump wrote:
> > After commit 8708ca01c0d libvirtd consistently aborts with "stack
> > smashing detected" when nodedev driver is initialized.
> >
> > This is caused by nlmsg_parse() being told that its array of nlattr*
> > has CTRL_CMD_MAX (10) entries, when in fact it is declared to have
> > CTRL_ATTR_MAX (8) entries. Since all the entries are initialized to
> > NULL, the result is that nlmsg_parse is overwriting 2*(sizof(nlattr*))
> > bytes outside the array.
> >
> > Signed-off-by: Laine Stump <laine at laine.org>
> > ---
> >
> > V1 was posted by jdenemar. It fixed the problem, but it was changing
> > the wrong line of code:
> >
> > https://www.redhat.com/archives/libvir-list/2017-September/msg00657.html
> >
>
> Reviewed-by: John Ferlan <jferlan at redhat.com>
>
> John
>
> (or ACK if you prefer - I'm just so used to the R-b now)
I pushed this patch.
Jirka
More information about the libvir-list
mailing list