提交 0a6047ee 编写于 作者: L Linus Torvalds

Fix vsnprintf off-by-one bug

The recent vsnprintf() fix introduced an off-by-one, and it's now
possible to overrun the target buffer by one byte.

The "end" pointer points to past the end of the buffer, so if we
have to truncate the result, it needs to be done though "end[-1]".

[ This is just an alternate and simpler patch to one proposed by Andrew
  and Jeremy, who actually noticed the problem ]
Acked-by: NAndrew Morton <akpm@osdl.org>
Acked-by: NJeremy Fitzhardinge <jeremy@goop.org>
Signed-off-by: NLinus Torvalds <torvalds@osdl.org>
上级 27d68a36
......@@ -489,7 +489,7 @@ int vsnprintf(char *buf, size_t size, const char *fmt, va_list args)
if (str < end)
*str = '\0';
else
*end = '\0';
end[-1] = '\0';
}
/* the trailing null byte doesn't count towards the total */
return str-buf;
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册