[igt-dev] [PATCH i-g-t] tests/testdisplay: fix heap overflow

Ser, Simon simon.ser at intel.com
Wed Mar 20 07:43:45 UTC 2019


We need to copy the terminating NULL byte too.

Signed-off-by: Simon Ser <simon.ser at intel.com>
---
 tests/testdisplay.c | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/tests/testdisplay.c b/tests/testdisplay.c
index b3657264..ff208384 100644
--- a/tests/testdisplay.c
+++ b/tests/testdisplay.c
@@ -563,17 +563,17 @@ static gboolean input_event(GIOChannel *source,
GIOCondition condition,
 	return TRUE;
 }
 
-static void enter_exec_path( char **argv )
+static void enter_exec_path(char **argv)
 {
 	char *exec_path = NULL;
 	char *pos = NULL;
 	short len_path = 0;
 	int ret;
 
-	len_path = strlen( argv[0] );
-	exec_path = (char*) malloc(len_path);
+	len_path = strlen(argv[0]);
+	exec_path = (char*) malloc(len_path + 1);
 
-	memcpy(exec_path, argv[0], len_path);
+	memcpy(exec_path, argv[0], len_path + 1);
 	pos = strrchr(exec_path, '/');
 	if (pos != NULL)
 		*(pos+1) = '\0';
-- 
2.21.0

---------------------------------------------------------------------
Intel Finland Oy
Registered Address: PL 281, 00181 Helsinki 
Business Identity Code: 0357606 - 4 
Domiciled in Helsinki 

This e-mail and any attachments may contain confidential material for
the sole use of the intended recipient(s). Any review or distribution
by others is strictly prohibited. If you are not the intended
recipient, please contact the sender and delete all copies.


More information about the igt-dev mailing list