[prev in list] [next in list] [prev in thread] [next in thread]
List: linux-netdev
Subject: Re: [PATCH] SUNRPC: Replace strlcpy() with strscpy()
From: Kees Cook <keescook () chromium ! org>
Date: 2023-11-30 20:43:31
Message-ID: 170137700879.3640204.581331941374933494.b4-ty () chromium ! org
[Download RAW message or body]
On Tue, 14 Nov 2023 09:54:18 -0800, Kees Cook wrote:
> strlcpy() reads the entire source buffer first. This read may exceed
> the destination size limit. This is both inefficient and can lead
> to linear read overflows if a source string is not NUL-terminated[1].
> Additionally, it returns the size of the source string, not the
> resulting size of the destination string. In an effort to remove strlcpy()
> completely[2], replace strlcpy() here with strscpy().
>
> [...]
Applied to for-next/hardening, thanks!
[1/1] SUNRPC: Replace strlcpy() with strscpy()
https://git.kernel.org/kees/c/cb6d2fd30ddd
Take care,
--
Kees Cook
[prev in list] [next in list] [prev in thread] [next in thread]
Configure |
About |
News |
Add a list |
Sponsored by KoreLogic