Received: by 10.223.185.111 with SMTP id b44csp917101wrg; Fri, 9 Mar 2018 16:48:53 -0800 (PST) X-Google-Smtp-Source: AG47ELsPnz/s2L6y4I9e+KaaG13F4Dg2gdqiElAzVZnwhuPEQ7wrdnRQTAb6Cf96PgAH2hczSiLi X-Received: by 2002:a17:902:a985:: with SMTP id bh5-v6mr378867plb.35.1520642933453; Fri, 09 Mar 2018 16:48:53 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1520642933; cv=none; d=google.com; s=arc-20160816; b=noEQCib4H3agHqg7rf67xMT/6q03VIzw6f5JDm4rj2hFXzJFU/Pnaer/cytspVh7hK k5uuQ28XNH5IPJEMZFUj/snbLflj0fUQ5UhL7iIlHxPB54vUmAxX6ZRJFnKfOKzphy1p s3qV1INsndTau9R77ewxey7MC7ccrpFuw9jILv2KkjlSrKVecZzh+mXRs7db40arJFl2 wsUVOHPbQM8Op+SL25IhpkISYK32/9X+opzlAR9J0Tfa7E8x66lzN41bC0l/LuCqVdtE VLILDna3pZXUraXaVtIif7E3p2KFmjRb6/XumzHq56S/WwseEJueTP/dw5iKzgFb+tfR cWiQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:mime-version:user-agent:references :in-reply-to:message-id:date:subject:cc:to:from :arc-authentication-results; bh=bN56o2FSyr6HCk1ViJiZ0KckLdRJ6yHwHcAkMVqsOk8=; b=TKgoV09JVILq5yCXK8LzRfRJodiI0yppqbtGwih/wHKAYeTOq642oG8MXd75Nh1AgM hHIx9P9bbQhLOmlZ+yBDXfEvxRE218HYfpRzFA7ao6ukKlpLujKS53lrQa635bOJbXVq MG0FFr3HOKbuHzZDfJeUNIDU/OAIrPavyrri9uYs0KNdicNzOgc++o1KzaeKyIbaniwr jJQMQIEnJ9x8zVaNheA8n4XTAjvwPinp2qSJa5Bbbb6F0qrbrqQ2ALCU+NDJmTgrVBb9 8xQekPuVvjPZcfM0v5qFQWw1078FyIbdN+S5gAFjW0ut0c786v82X0bPtaZOPzP1WZDS XB6Q== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id s3-v6si1761365plb.4.2018.03.09.16.48.39; Fri, 09 Mar 2018 16:48:53 -0800 (PST) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S933181AbeCJATw (ORCPT + 99 others); Fri, 9 Mar 2018 19:19:52 -0500 Received: from mail.linuxfoundation.org ([140.211.169.12]:38846 "EHLO mail.linuxfoundation.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S933141AbeCJATu (ORCPT ); Fri, 9 Mar 2018 19:19:50 -0500 Received: from localhost (unknown [185.236.200.248]) by mail.linuxfoundation.org (Postfix) with ESMTPSA id 5F038F73; Sat, 10 Mar 2018 00:19:49 +0000 (UTC) From: Greg Kroah-Hartman To: linux-kernel@vger.kernel.org Cc: Greg Kroah-Hartman , stable@vger.kernel.org, Nathan Sullivan , Zach Brown , Jacek Anaszewski , Willy Tarreau , Vlastimil Babka Subject: [PATCH 4.4 15/36] leds: do not overflow sysfs buffer in led_trigger_show Date: Fri, 9 Mar 2018 16:18:31 -0800 Message-Id: <20180310001808.135271502@linuxfoundation.org> X-Mailer: git-send-email 2.16.2 In-Reply-To: <20180310001807.213987241@linuxfoundation.org> References: <20180310001807.213987241@linuxfoundation.org> User-Agent: quilt/0.65 X-stable: review MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org 4.4-stable review patch. If anyone has any objections, please let me know. ------------------ From: Nathan Sullivan commit 3b9b95363c45365d606ad4bbba16acca75fdf6d3 upstream. Per the documentation, use scnprintf instead of sprintf to ensure there is never more than PAGE_SIZE bytes of trigger names put into the buffer. Signed-off-by: Nathan Sullivan Signed-off-by: Zach Brown Signed-off-by: Jacek Anaszewski Cc: Willy Tarreau Cc: Vlastimil Babka Signed-off-by: Greg Kroah-Hartman --- drivers/leds/led-triggers.c | 12 +++++++----- 1 file changed, 7 insertions(+), 5 deletions(-) --- a/drivers/leds/led-triggers.c +++ b/drivers/leds/led-triggers.c @@ -88,21 +88,23 @@ ssize_t led_trigger_show(struct device * down_read(&led_cdev->trigger_lock); if (!led_cdev->trigger) - len += sprintf(buf+len, "[none] "); + len += scnprintf(buf+len, PAGE_SIZE - len, "[none] "); else - len += sprintf(buf+len, "none "); + len += scnprintf(buf+len, PAGE_SIZE - len, "none "); list_for_each_entry(trig, &trigger_list, next_trig) { if (led_cdev->trigger && !strcmp(led_cdev->trigger->name, trig->name)) - len += sprintf(buf+len, "[%s] ", trig->name); + len += scnprintf(buf+len, PAGE_SIZE - len, "[%s] ", + trig->name); else - len += sprintf(buf+len, "%s ", trig->name); + len += scnprintf(buf+len, PAGE_SIZE - len, "%s ", + trig->name); } up_read(&led_cdev->trigger_lock); up_read(&triggers_list_lock); - len += sprintf(len+buf, "\n"); + len += scnprintf(len+buf, PAGE_SIZE - len, "\n"); return len; } EXPORT_SYMBOL_GPL(led_trigger_show);