From b26c6609c2c25d12210bde0390c616c5483b64c6 Mon Sep 17 00:00:00 2001 From: Piyush Dhyani Date: Tue, 5 Jan 2021 12:15:32 +0530 Subject: [PATCH] msm: ipa: Fix string out of bound issue. Currently during RMNET_IOCTL_GET_MTU and RMNET_IOCTL_SET_MTU ioctls we can recieve not null terminated string for if_name which was resulting in string out of bound error while accessing the if_name. Now adding null character at the end of string to prevent access beyond its size. Change-Id: I4d82a4b491f04a85d6ab4f0211671520156f7c61 Signed-off-by: Piyush Dhyani --- drivers/platform/msm/ipa/ipa_v3/rmnet_ipa.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/drivers/platform/msm/ipa/ipa_v3/rmnet_ipa.c b/drivers/platform/msm/ipa/ipa_v3/rmnet_ipa.c index 4e447e453acb..396802dac652 100644 --- a/drivers/platform/msm/ipa/ipa_v3/rmnet_ipa.c +++ b/drivers/platform/msm/ipa/ipa_v3/rmnet_ipa.c @@ -2095,6 +2095,8 @@ static int ipa3_wwan_ioctl(struct net_device *dev, struct ifreq *ifr, int cmd) /* Get MTU */ case RMNET_IOCTL_GET_MTU: mux_channel = rmnet_ipa3_ctx->mux_channel; + ext_ioctl_data.u.mtu_params.if_name + [IFNAMSIZ-1] = '\0'; rmnet_index = find_vchannel_name_index(ext_ioctl_data.u.mtu_params.if_name); @@ -2115,6 +2117,8 @@ static int ipa3_wwan_ioctl(struct net_device *dev, struct ifreq *ifr, int cmd) /* Set MTU */ case RMNET_IOCTL_SET_MTU: mux_channel = rmnet_ipa3_ctx->mux_channel; + ext_ioctl_data.u.mtu_params.if_name + [IFNAMSIZ-1] = '\0'; rmnet_index = find_vchannel_name_index(ext_ioctl_data.u.mtu_params.if_name);