efi: cper: fix snprintf() use in cper_dimm_err_location()
stable inclusion from linux-4.19.194 commit dd47a33e11fdd6c9d31570500e6ecc369ba1f08e -------------------------------- [ Upstream commit 942859d9 ] snprintf() should be given the full buffer size, not one less. And it guarantees nul-termination, so doing it manually afterwards is pointless. It's even potentially harmful (though probably not in practice because CPER_REC_LEN is 256), due to the "return how much would have been written had the buffer been big enough" semantics. I.e., if the bank and/or device strings are long enough that the "DIMM location ..." output gets truncated, writing to msg[n] is a buffer overflow. Signed-off-by:Rasmus Villemoes <linux@rasmusvillemoes.dk> Fixes: 3760cd20 ("CPER: Adjust code flow of some functions") Signed-off-by:
Ard Biesheuvel <ardb@kernel.org> Signed-off-by:
Sasha Levin <sashal@kernel.org> Signed-off-by:
Yang Yingliang <yangyingliang@huawei.com>
Loading
Please sign in to comment