mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
synced 2026-09-22 09:34:56 +02:00
lib/bootconfig: check bounds before writing in __xbc_open_brace()
commit560f763baaupstream. The bounds check for brace_index happens after the array write. While the current call pattern prevents an actual out-of-bounds access (the previous call would have returned an error), the write-before-check pattern is fragile and would become a real out-of-bounds write if the error return were ever not propagated. Move the bounds check before the array write so the function is self-contained and safe regardless of caller behavior. Link: https://lore.kernel.org/all/20260312191143.28719-3-objecting@objecting.org/ Fixes:ead1e19ad9("lib/bootconfig: Fix a bug of breaking existing tree nodes") Cc: stable@vger.kernel.org Signed-off-by: Josh Law <objecting@objecting.org> Signed-off-by: Masami Hiramatsu (Google) <mhiramat@kernel.org> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
This commit is contained in:
committed by
Greg Kroah-Hartman
parent
6e736a18cf
commit
bfbf1f286f
+1
-1
@@ -532,9 +532,9 @@ static char *skip_spaces_until_newline(char *p)
|
||||
static int __init __xbc_open_brace(char *p)
|
||||
{
|
||||
/* Push the last key as open brace */
|
||||
open_brace[brace_index++] = xbc_node_index(last_parent);
|
||||
if (brace_index >= XBC_DEPTH_MAX)
|
||||
return xbc_parse_error("Exceed max depth of braces", p);
|
||||
open_brace[brace_index++] = xbc_node_index(last_parent);
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user