4 ms·
I would be careful, a critical buffer overflow vulnerability was just found in the Douane kernel module: https://github.com/Douane/douane-dkms/commit/61023b91f
by awordnot 10y ago
I would be careful, a critical buffer overflow vulnerability was just found in the Douane kernel module: https://github.com/Douane/douane-dkms/commit/61023b91fbafab8e63d8c271ec25aa0929f2f643 https://github.com/Douane/douane-dkms/commit/61023b91fbafab8...
- q3k 10y agostrcpy() in a kernel module. This is quite horrifying.
- ori_b 10y agoAnd it's still wrong, since strncpy() doesn't null terminate: it null pads. That means that if the string is longer than the buffer, it will not be correctly terminated.
- ramchip 10y agoComments like this never fail to make me smile: + // Don't do anything if the process_path length is > PATH_LENGTH + if (strlen(process_path) > PATH_LENGTH) + return;