+2
−2
Loading
9p back-end first queries the size of an extended attribute, allocates space for it via g_malloc() and then retrieves its value into allocated buffer. Race between querying attribute size and retrieving its could lead to memory bytes disclosure. Use g_malloc0() to avoid it. Reported-by:Tuomas Tynkkynen <tuomas.tynkkynen@iki.fi> Signed-off-by:
Prasad J Pandit <pjp@fedoraproject.org> Signed-off-by:
Greg Kurz <groug@kaod.org>