From owner-cvs-all@FreeBSD.ORG Wed Mar 23 08:28:11 2005 Return-Path: Delivered-To: cvs-all@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 424AD16A503; Wed, 23 Mar 2005 08:28:07 +0000 (GMT) Received: from repoman.freebsd.org (repoman.freebsd.org [216.136.204.115]) by mx1.FreeBSD.org (Postfix) with ESMTP id 16B7043D55; Wed, 23 Mar 2005 08:28:07 +0000 (GMT) (envelope-from das@FreeBSD.org) Received: from repoman.freebsd.org (localhost [127.0.0.1]) by repoman.freebsd.org (8.13.1/8.13.1) with ESMTP id j2N8S6fZ022006; Wed, 23 Mar 2005 08:28:06 GMT (envelope-from das@repoman.freebsd.org) Received: (from das@localhost) by repoman.freebsd.org (8.13.1/8.13.1/Submit) id j2N8S6Ti022005; Wed, 23 Mar 2005 08:28:06 GMT (envelope-from das) Message-Id: <200503230828.j2N8S6Ti022005@repoman.freebsd.org> From: David Schultz Date: Wed, 23 Mar 2005 08:28:06 +0000 (UTC) To: src-committers@FreeBSD.org, cvs-src@FreeBSD.org, cvs-all@FreeBSD.org X-FreeBSD-CVS-Branch: HEAD Subject: cvs commit: src/sys/compat/svr4 svr4_stream.c X-BeenThere: cvs-all@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: CVS commit messages for the entire tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 23 Mar 2005 08:28:11 -0000 das 2005-03-23 08:28:06 UTC FreeBSD src repository Modified files: sys/compat/svr4 svr4_stream.c Log: Bounds check the user-supplied length used in a copyout() in svr4_do_getmsg(). In principle this bug could disclose data from kernel memory, but in practice, the SVR4 emulation layer is probably not functional enough to cause the relevant code path to be executed. In any case, the emulator has been disconnected from the build since 5.0-RELEASE. Found by: Coverity Prevent analysis tool Revision Changes Path 1.53 +2 -0 src/sys/compat/svr4/svr4_stream.c