Blame SOURCES/lvm2-2_02_178-allocation-Avoid-exceeding-array-bounds-in-allocatio.patch

f0aa83
From ce8663ee13e68b8f21dce6e2cf612d3809519787 Mon Sep 17 00:00:00 2001
f0aa83
From: Alasdair G Kergon <agk@redhat.com>
f0aa83
Date: Wed, 10 Jan 2018 02:03:32 +0000
f0aa83
Subject: [PATCH 12/25] allocation: Avoid exceeding array bounds in allocation
f0aa83
 tag code
f0aa83
f0aa83
If _limit_to_one_area_per_tag() changes nothing it writes beyond
f0aa83
the array.
f0aa83
f0aa83
(cherry picked from commit bacc94233368cf136b55e2574e969e7f53b31c6c)
f0aa83
f0aa83
Conflicts:
f0aa83
	WHATS_NEW
f0aa83
---
f0aa83
 WHATS_NEW               | 4 ++++
f0aa83
 lib/metadata/lv_manip.c | 3 ++-
f0aa83
 2 files changed, 6 insertions(+), 1 deletion(-)
f0aa83
f0aa83
diff --git a/WHATS_NEW b/WHATS_NEW
f0aa83
index 2163a5e..9375a86 100644
f0aa83
--- a/WHATS_NEW
f0aa83
+++ b/WHATS_NEW
f0aa83
@@ -1,3 +1,7 @@
f0aa83
+Version 2.02.178 - 
f0aa83
+=====================================
f0aa83
+  Avoid exceeding array bounds in allocation tag processing.
f0aa83
+
f0aa83
 Version 2.02.177 - 18th December 2017
f0aa83
 =====================================
f0aa83
   When writing text metadata content, use complete 4096 byte blocks.
f0aa83
diff --git a/lib/metadata/lv_manip.c b/lib/metadata/lv_manip.c
f0aa83
index 70dc2d9..ac30dad 100644
f0aa83
--- a/lib/metadata/lv_manip.c
f0aa83
+++ b/lib/metadata/lv_manip.c
f0aa83
@@ -2737,7 +2737,8 @@ static int _limit_to_one_area_per_tag(struct alloc_handle *ah, struct alloc_stat
f0aa83
 		s++;
f0aa83
 	}
f0aa83
 
f0aa83
-	alloc_state->areas[u].pva = NULL;
f0aa83
+	if (u < alloc_state->areas_size)
f0aa83
+		alloc_state->areas[u].pva = NULL;
f0aa83
 
f0aa83
 	return 1;
f0aa83
 }
f0aa83
-- 
f0aa83
1.8.3.1
f0aa83