码迷,mamicode.com
首页 > 移动开发 > 详细

CVE-2016-2502-drivers/usb/gadget/f_serial.c in the Qualcomm USB driver in Android. Buffer Overflow Vulnerability reported by #plzdonthackme, Soctt.

时间:2016-08-15 14:17:40      阅读:187      评论:0      收藏:0      [点我收藏+]

标签:

CVE-2016-2502-drivers/usb/gadget/f_serial.c in the Qualcomm USB driver in Android.
Buffer Overflow Vulnerability reported by #plzdonthackme, Soctt. 

struct ioctl_smd_write_arg_type {
        char                *buf;
        unsigned int        size;
};
#define GSERIAL_BUF_LEN  256
char smd_write_buf[GSERIAL_BUF_LEN];
struct ioctl_smd_write_arg_type smd_write_arg;
...
case GSERIAL_SMD_WRITE:
   if (copy_from_user(&smd_write_arg, argp,
       sizeof(smd_write_arg))) {
   ...
   //Patch
   //if (smd_write_arg.size > GSERIAL_BUF_LEN )
   //    pr_err("%s: dont trigger the BoD vuln.", __func__);
       
   if (copy_from_user(smd_write_buf, smd_write_arg.buf,
        smd_write_arg.size)) // Bof vuln.

CVE-2016-2502-drivers/usb/gadget/f_serial.c in the Qualcomm USB driver in Android. Buffer Overflow Vulnerability reported by #plzdonthackme, Soctt.

标签:

原文地址:http://www.cnblogs.com/bittorrent/p/5772636.html

(0)
(0)
   
举报
评论 一句话评论(0
登录后才能评论!
© 2014 mamicode.com 版权所有  联系我们:gaon5@hotmail.com
迷上了代码!