summaryrefslogtreecommitdiff
path: root/mm/vmalloc.c
diff options
context:
space:
mode:
authorDan Carpenter <dan.carpenter@oracle.com>2014-07-17 10:50:45 (GMT)
committerDavid S. Miller <davem@davemloft.net>2014-07-17 23:47:50 (GMT)
commita28d0e873d2899bd750ae495f84fe9c1a2f53809 (patch)
treec298871f2dfa4dc8f93e0f2928aa844b1cda20f1 /mm/vmalloc.c
parentcc25eaae238ddd693aa5eaa73e565d8ff4915f6e (diff)
downloadlinux-a28d0e873d2899bd750ae495f84fe9c1a2f53809.tar.xz
wan/x25_asy: integer overflow in x25_asy_change_mtu()
If "newmtu * 2 + 4" is too large then it can cause an integer overflow leading to memory corruption. Eric Dumazet suggests that 65534 is a reasonable upper limit. Btw, "newmtu" is not allowed to be a negative number because of the check in dev_set_mtu(), so that's ok. Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com> Signed-off-by: David S. Miller <davem@davemloft.net>
Diffstat (limited to 'mm/vmalloc.c')
0 files changed, 0 insertions, 0 deletions