diff options
| author | Cy Schubert <cy@FreeBSD.org> | 2026-02-04 17:27:23 +0000 |
|---|---|---|
| committer | Cy Schubert <cy@FreeBSD.org> | 2026-02-04 20:46:20 +0000 |
| commit | e40817302ebdf89df2f3bcd679fb7f2a18c244dc (patch) | |
| tree | e50cff0b0c7b813daaa91ce4d7709cc744a64c65 /cddl/usr.sbin/dtrace/tests/common/env | |
| parent | fe8105de1485063a02ff25e686761247f78aaed9 (diff) | |
The destination buffer is FR_GROUPLEN (16 bytes) in length. When
gname is created, the userspace utilities correctly use FR_GROUPLEN
as the buffer length. The kernel should also limit its copy operation to
FR_GROUPLEN bytes to avoid any user written code from exploiting this
vulnerability.
Reported by: Ilja Van Sprundel <ivansprundel@ioactive.com>
MFC after: 1 week
Diffstat (limited to 'cddl/usr.sbin/dtrace/tests/common/env')
0 files changed, 0 insertions, 0 deletions
