[SCSI] nsp_cs: fix buf overflow
authorJiri Slaby <jirislaby@gmail.com>
Sat, 8 Aug 2009 09:36:06 +0000 (11:36 +0200)
committerJames Bottomley <James.Bottomley@suse.de>
Sat, 22 Aug 2009 22:52:22 +0000 (17:52 -0500)
In nsp_cs_config there is a wrong struct nsp_cs_configdata allocation.
It allocates only sizeof(pointer to nsp_cs_configdata) for a whole
structure. Add a dereference to the sizeof to allocate
sizeof(nsp_cs_configdata).

Signed-off-by: Jiri Slaby <jirislaby@gmail.com>
Signed-off-by: James Bottomley <James.Bottomley@suse.de>
drivers/scsi/pcmcia/nsp_cs.c

index 70b60ade049eb6eec28612a0307a14284b9adb8b..e32c344d7ad853c03f4a5338b2786e3a72cdc247 100644 (file)
@@ -1713,7 +1713,7 @@ static int nsp_cs_config(struct pcmcia_device *link)
 
        nsp_dbg(NSP_DEBUG_INIT, "in");
 
-       cfg_mem = kzalloc(sizeof(cfg_mem), GFP_KERNEL);
+       cfg_mem = kzalloc(sizeof(*cfg_mem), GFP_KERNEL);
        if (!cfg_mem)
                return -ENOMEM;
        cfg_mem->data = data;