Blame SOURCES/0092-iplink_can-Prevent-overstepping-array-bounds.patch

36cfb7
From 4c775c035e2751b1aec52dcc2ca0e4fc99bac793 Mon Sep 17 00:00:00 2001
36cfb7
From: Andrea Claudi <aclaudi@redhat.com>
36cfb7
Date: Mon, 29 Apr 2019 20:08:07 +0200
36cfb7
Subject: [PATCH] iplink_can: Prevent overstepping array bounds
36cfb7
36cfb7
Bugzilla: https://bugzilla.redhat.com/show_bug.cgi?id=1465646
36cfb7
Upstream Status: iproute2.git commit 258b7c0fa70c2
36cfb7
36cfb7
commit 258b7c0fa70c2d6b5f9776cc35c38c80b4ee5752
36cfb7
Author: Phil Sutter <phil@nwl.cc>
36cfb7
Date:   Mon Aug 21 11:27:00 2017 +0200
36cfb7
36cfb7
    iplink_can: Prevent overstepping array bounds
36cfb7
36cfb7
    can_state_names array contains at most CAN_STATE_MAX fields, so allowing
36cfb7
    an index to it to be equal to that number is wrong. While here, also
36cfb7
    make sure the array is indeed that big so nothing bad happens if
36cfb7
    CAN_STATE_MAX ever increases.
36cfb7
36cfb7
    Signed-off-by: Phil Sutter <phil@nwl.cc>
36cfb7
---
36cfb7
 ip/iplink_can.c | 4 ++--
36cfb7
 1 file changed, 2 insertions(+), 2 deletions(-)
36cfb7
36cfb7
diff --git a/ip/iplink_can.c b/ip/iplink_can.c
36cfb7
index 20d4d37d0d087..4133a658a059e 100644
36cfb7
--- a/ip/iplink_can.c
36cfb7
+++ b/ip/iplink_can.c
36cfb7
@@ -241,7 +241,7 @@ static int can_parse_opt(struct link_util *lu, int argc, char **argv,
36cfb7
 	return 0;
36cfb7
 }
36cfb7
 
36cfb7
-static const char *can_state_names[] = {
36cfb7
+static const char *can_state_names[CAN_STATE_MAX] = {
36cfb7
 	[CAN_STATE_ERROR_ACTIVE] = "ERROR-ACTIVE",
36cfb7
 	[CAN_STATE_ERROR_WARNING] = "ERROR-WARNING",
36cfb7
 	[CAN_STATE_ERROR_PASSIVE] = "ERROR-PASSIVE",
36cfb7
@@ -265,7 +265,7 @@ static void can_print_opt(struct link_util *lu, FILE *f, struct rtattr *tb[])
36cfb7
 	if (tb[IFLA_CAN_STATE]) {
36cfb7
 		uint32_t state = rta_getattr_u32(tb[IFLA_CAN_STATE]);
36cfb7
 
36cfb7
-		fprintf(f, "state %s ", state <= CAN_STATE_MAX ?
36cfb7
+		fprintf(f, "state %s ", state < CAN_STATE_MAX ?
36cfb7
 			can_state_names[state] : "UNKNOWN");
36cfb7
 	}
36cfb7
 
36cfb7
-- 
36cfb7
2.20.1
36cfb7