diff options
author | Mathias Krause <minipli@googlemail.com> | 2012-07-12 08:46:54 +0200 |
---|---|---|
committer | Greg Kroah-Hartman <gregkh@linuxfoundation.org> | 2013-03-28 12:06:04 -0700 |
commit | 89e2149fdbd22db4c354df58f2939b8878e6f10d (patch) | |
tree | d0c1f97566c2449bbb898c8df5725a42ba374d23 | |
parent | c18508394610b47964ef6c2d4d71b85873ce10fe (diff) | |
download | lwn-89e2149fdbd22db4c354df58f2939b8878e6f10d.tar.gz lwn-89e2149fdbd22db4c354df58f2939b8878e6f10d.zip |
isofs: avoid info leak on export
commit fe685aabf7c8c9f138e5ea900954d295bf229175 upstream.
For type 1 the parent_offset member in struct isofs_fid gets copied
uninitialized to userland. Fix this by initializing it to 0.
Signed-off-by: Mathias Krause <minipli@googlemail.com>
Signed-off-by: Jan Kara <jack@suse.cz>
Cc: Ben Hutchings <ben@decadent.org.uk>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
-rw-r--r-- | fs/isofs/export.c | 1 |
1 files changed, 1 insertions, 0 deletions
diff --git a/fs/isofs/export.c b/fs/isofs/export.c index 516eb21895c6..fd88add6ca46 100644 --- a/fs/isofs/export.c +++ b/fs/isofs/export.c @@ -135,6 +135,7 @@ isofs_export_encode_fh(struct dentry *dentry, len = 3; fh32[0] = ei->i_iget5_block; fh16[2] = (__u16)ei->i_iget5_offset; /* fh16 [sic] */ + fh16[3] = 0; /* avoid leaking uninitialized data */ fh32[2] = inode->i_generation; if (connectable && !S_ISDIR(inode->i_mode)) { struct inode *parent; |