首页 > 移动平台 > 详细

CVE-2016-2502-drivers/usb/gadget/f_serial.c in the Qualcomm USB driver in Android. Buffer Overflow Vulnerability reported by #plzdonthackme, Soctt.

时间:2016-08-15 14:15:44      阅读:449      评论:0      收藏:0      [点我收藏+]

CVE-2016-2502-drivers/usb/gadget/f_serial.c in the Qualcomm USB driver in Android.
Buffer Overflow Vulnerability reported by #plzdonthackme, Soctt. 

struct ioctl_smd_write_arg_type {
        char                *buf;
        unsigned int        size;
};
#define GSERIAL_BUF_LEN  256
char smd_write_buf[GSERIAL_BUF_LEN];
struct ioctl_smd_write_arg_type smd_write_arg;
...
case GSERIAL_SMD_WRITE:
   if (copy_from_user(&smd_write_arg, argp,
       sizeof(smd_write_arg))) {
   ...
   //Patch
   //if (smd_write_arg.size > GSERIAL_BUF_LEN )
   //    pr_err("%s: dont trigger the BoD vuln.", __func__);
       
   if (copy_from_user(smd_write_buf, smd_write_arg.buf,
        smd_write_arg.size)) // Bof vuln.

CVE-2016-2502-drivers/usb/gadget/f_serial.c in the Qualcomm USB driver in Android. Buffer Overflow Vulnerability reported by #plzdonthackme, Soctt.

原文:http://www.cnblogs.com/bittorrent/p/5772636.html

(0)
(0)
   
举报
评论 一句话评论(0
关于我们 - 联系我们 - 留言反馈 - 联系我们:wmxa8@hotmail.com
© 2014 bubuko.com 版权所有
打开技术之扣,分享程序人生!