Martin Wilck 9309a1
From: Martin Wilck <mwilck@suse.com>
Martin Wilck 9309a1
Date: Mon, 27 Nov 2017 23:47:34 +0100
Martin Wilck 9309a1
Subject: scsi: scsi_devinfo: handle non-terminated strings
Martin Wilck 9309a1
Git-commit: ba69ead9e9e9bb3cec5faf03526c36764ac8942a
Takashi Iwai 5407fb
Patch-mainline: v4.15-rc4
Martin Wilck 9309a1
References: bsc#1062941, bsc#1037404, bsc#1012523, bsc#1038299
Martin Wilck 9309a1
Martin Wilck 9309a1
devinfo->vendor and devinfo->model aren't necessarily
Martin Wilck 9309a1
zero-terminated.
Martin Wilck 9309a1
Martin Wilck 9309a1
Fixes: b8018b973c7c "scsi_devinfo: fixup string compare"
Martin Wilck 9309a1
Signed-off-by: Martin Wilck <mwilck@suse.com>
Martin Wilck 9309a1
Reviewed-by: Bart Van Assche <bart.vanassche@wdc.com>
Martin Wilck 9309a1
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Martin Wilck 9309a1
---
Martin Wilck 9309a1
 drivers/scsi/scsi_devinfo.c | 5 +++--
Martin Wilck 9309a1
 1 file changed, 3 insertions(+), 2 deletions(-)
Martin Wilck 9309a1
Martin Wilck 9309a1
diff --git a/drivers/scsi/scsi_devinfo.c b/drivers/scsi/scsi_devinfo.c
Martin Wilck 9309a1
index 78d4aa8df675..b256d4cbd3ad 100644
Martin Wilck 9309a1
--- a/drivers/scsi/scsi_devinfo.c
Martin Wilck 9309a1
+++ b/drivers/scsi/scsi_devinfo.c
Martin Wilck 9309a1
@@ -458,7 +458,8 @@ static struct scsi_dev_info_list *scsi_dev_info_list_find(const char *vendor,
Martin Wilck 9309a1
 			/*
Martin Wilck 9309a1
 			 * vendor strings must be an exact match
Martin Wilck 9309a1
 			 */
Martin Wilck 9309a1
-			if (vmax != strlen(devinfo->vendor) ||
Martin Wilck 9309a1
+			if (vmax != strnlen(devinfo->vendor,
Martin Wilck 9309a1
+					    sizeof(devinfo->vendor)) ||
Martin Wilck 9309a1
 			    memcmp(devinfo->vendor, vskip, vmax))
Martin Wilck 9309a1
 				continue;
Martin Wilck 9309a1
 
Martin Wilck 9309a1
@@ -466,7 +467,7 @@ static struct scsi_dev_info_list *scsi_dev_info_list_find(const char *vendor,
Martin Wilck 9309a1
 			 * @model specifies the full string, and
Martin Wilck 9309a1
 			 * must be larger or equal to devinfo->model
Martin Wilck 9309a1
 			 */
Martin Wilck 9309a1
-			mlen = strlen(devinfo->model);
Martin Wilck 9309a1
+			mlen = strnlen(devinfo->model, sizeof(devinfo->model));
Martin Wilck 9309a1
 			if (mmax < mlen || memcmp(devinfo->model, mskip, mlen))
Martin Wilck 9309a1
 				continue;
Martin Wilck 9309a1
 			return devinfo;
Martin Wilck 9309a1