NFSv4.1: integer overflow in decode_cb_sequence_args()
authorDan Carpenter <dan.carpenter@oracle.com>
Tue, 12 Jun 2012 07:37:08 +0000 (10:37 +0300)
committerTrond Myklebust <Trond.Myklebust@netapp.com>
Tue, 12 Jun 2012 13:54:36 +0000 (09:54 -0400)
commit0439f31c35d1da0b28988b308ea455e38e6a350d
tree3d59dd6250c47968f5d6e521d3442525146660a4
parent92123e068efa310b09e9943ac1cfd10ff6b6d2e4
NFSv4.1: integer overflow in decode_cb_sequence_args()

This seems like it could overflow on 32 bits.  Use kmalloc_array() which
has overflow protection built in.

Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
Signed-off-by: Trond Myklebust <Trond.Myklebust@netapp.com>
fs/nfs/callback_xdr.c