В ядре Linux устранена следующая уязвимость:
lib/ucs2_string.c: исправлено чтение за пределами границ в ucs2_strnlen(). Серия патчей «lib/ucs2_string.c: исправлено чтение за пределами границ»
ucs2_strnlen()", v2. В этой серии исправлено чтение за пределами границ с отклонением на единицу в ucs2_strnlen().
Первый патч - настоящее исправление, второй патч идет в качестве бонуса и
исправляет отступы кода. Этот патч (из 2):
ucs2_strnlen() проверяет текущий символ, прежде чем проверить,
Достигнута максимальная длина, предоставленная вызывающим абонентом. Если ввод не
В пределах этой границы завершается NUL, цикл может прочитать один ucs2_char_t после
предел.
Проверьте длину перед разыменованием, чтобы избежать отклонения на единицу. чтение за пределами поля.
Показать оригинальное описание (EN)
In the Linux kernel, the following vulnerability has been resolved: lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen() Patch series "lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen()", v2. This series fixes an off-by-one out-of-bounds read in ucs2_strnlen(). The first patch is the real fix, the second patch comes as a bonus and fixes the code indentation. This patch (of 2): ucs2_strnlen() checks the current character before checking whether the caller-provided maximum length has been reached. If the input is not NUL-terminated within that bound, the loop can read one ucs2_char_t past the limit. Test the length before dereferencing to prevent an off-by-one out-of-bounds read.