mirror of
https://github.com/ibm-s390-linux/s390-tools.git
synced 2026-08-05 02:14:52 +00:00
cdabf280ac
read_page_buf() uses the file-controlled pg_hdr->size directly as the byte count for zg_read() into fixed stack buffers of PAGE_SIZE. A crafted LKCD dump with pg_hdr->size > PAGE_SIZE overflows the buffer and smashes the stack frame. A size of 0 for a raw page silently produces uninitialised data. Enforce page header size constraints following crash-utility's logic: - Compressed or Raw pages with size > PAGE_SIZE are invalid; exit with an error. - Raw pages with size 0 contain no data in the file; fill the output buffer with zeros without reading. - Compressed pages with size 0 are caught by the uncompress() return code check. - Raw pages with size != PAGE_SIZE are invalid; exit with an error. Check the return code of uncompress() and exit with an error if decompression fails, rather than silently proceeding with an incomplete output buffer. Signed-off-by: Mikhail Zaslonko <zaslonko@linux.ibm.com> Reviewed-by: Alexander Egorenkov <egorenar@linux.ibm.com> Signed-off-by: Jan Höppner <hoeppner@linux.ibm.com>
8.0 KiB
8.0 KiB