apparmor: do not expose kernel stack
authorHeinrich Schuchardt <xypron.glpk@gmx.de>
Fri, 10 Jun 2016 21:34:26 +0000 (23:34 +0200)
committerWilly Tarreau <w@1wt.eu>
Tue, 20 Jun 2017 12:04:13 +0000 (14:04 +0200)
commit f4ee2def2d70692ccff0d55353df4ee594fd0017 upstream.

Do not copy uninitalized fields th.td_hilen, th.td_data.

Signed-off-by: Heinrich Schuchardt <xypron.glpk@gmx.de>
Signed-off-by: John Johansen <john.johansen@canonical.com>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
Signed-off-by: Willy Tarreau <w@1wt.eu>
security/apparmor/match.c

index 10d824bc35772dbf13d51a67e4775713000da2d2..704b0eb258010a693cbb8b2d1fa30293b910155e 100644 (file)
@@ -61,7 +61,9 @@ static struct table_header *unpack_table(char *blob, size_t bsize)
 
        table = kvmalloc(tsize);
        if (table) {
-               *table = th;
+               table->td_id = th.td_id;
+               table->td_flags = th.td_flags;
+               table->td_lolen = th.td_lolen;
                if (th.td_flags == YYTD_DATA8)
                        UNPACK_ARRAY(table->td_data, blob, th.td_lolen,
                                     u8, byte_to_byte);