commit | ef26a5a6eadb7cd0637e1e9e246cd42505b8ec8c | [log] [tgz] |
---|---|---|
author | David Howells <dhowells@redhat.com> | Tue May 22 15:56:13 2012 +0100 |
committer | Rusty Russell <rusty@rustcorp.com.au> | Wed May 23 22:28:53 2012 +0930 |
tree | 94f8b1998d94080a842f94529f0d95cfe1bcc53a | |
parent | 3c7ec94d2c4a67d9663a080aa5080134308261c4 [diff] |
Guard check in module loader against integer overflow The check: if (len < hdr->e_shoff + hdr->e_shnum * sizeof(Elf_Shdr)) may not work if there's an overflow in the right-hand side of the condition. Signed-off-by: David Howells <dhowells@redhat.com> Signed-off-by: Rusty Russell <rusty@rustcorp.com.au>