f2fs: check memory boundary by insane namelen
mainline inclusion from mainline-v5.0-rc1 commit 4e240d1b category: bugfix bugzilla: 13690 CVE: CVE-2019-9445 ------------------------------------------------- If namelen is corrupted to have very long value, fill_dentries can copy wrong memory area. Reviewed-by: NChao Yu <yuchao0@huawei.com> Signed-off-by: NJaegeuk Kim <jaegeuk@kernel.org> Signed-off-by: NYang Yingliang <yangyingliang@huawei.com> Reviewed-by: NWei Fang <fangwei1@huawei.com> Signed-off-by: NYang Yingliang <yangyingliang@huawei.com>
Showing
想要评论请 注册 或 登录