Summary: | A possible out of bounds of memory in netinet/libalias/alias_sctp.c. | ||
---|---|---|---|
Product: | Base System | Reporter: | logwang <logwang> |
Component: | kern | Assignee: | Michael Tuexen <tuexen> |
Status: | Closed FIXED | ||
Severity: | Affects Some People | CC: | tuexen |
Priority: | --- | Flags: | tuexen:
mfc-stable11+
tuexen: mfc-stable10+ |
Version: | CURRENT | ||
Hardware: | Any | ||
OS: | Any |
Description
logwang
2017-12-05 07:14:38 UTC
(In reply to logwang from comment #0) a description mistake: sn_calloc will be expanded to sizeof(struct sctpTimerQ)*SN_MAX_TIMER+2 A commit references this bug: Author: tuexen Date: Tue Dec 26 14:37:48 UTC 2017 New revision: 327203 URL: https://svnweb.freebsd.org/changeset/base/327203 Log: Allow the first (and second) argument of sn_calloc() be a sum. This fixes a bug reported in https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=224103 PR: 224103 Changes: head/sys/netinet/libalias/alias_sctp.c A commit references this bug: Author: tuexen Date: Sun Apr 8 14:09:27 UTC 2018 New revision: 332276 URL: https://svnweb.freebsd.org/changeset/base/332276 Log: MFC r327203: Allow the first (and second) argument of sn_calloc() be a sum. This fixes a bug reported in https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=224103 PR: 224103 Changes: _U stable/11/ stable/11/sys/netinet/libalias/alias_sctp.c A commit references this bug: Author: tuexen Date: Sun Apr 8 16:24:37 UTC 2018 New revision: 332282 URL: https://svnweb.freebsd.org/changeset/base/332282 Log: MFC r327203: Allow the first (and second) argument of sn_calloc() be a sum. This fixes a bug reported in https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=224103 PR: 224103 Changes: _U stable/10/ stable/10/sys/netinet/libalias/alias_sctp.c |