[PATCH] [BZ 17542] sunrpc: conditional jump depends on uninitialised value in svc_getreq_common

Siddhesh Poyarekar siddhesh@redhat.com
Wed Nov 5 09:38:00 GMT 2014


On Wed, Nov 05, 2014 at 10:31:31AM +0100, Andreas Schwab wrote:
> > That is likely an application bug, but it might not be a bad idea to
> > include the patch anyway.  Failing the NULL check and returning seems
> > better than allowing to dereference arbitrary pointer values.
> 
> But what does this have to do with "sock > _rpc_dtablesize()"?

Nothing.  That analysis is incorrect AFAIK and it seems to be a
failure in calling xprt_register as you pointed out, which should be
an application bug.

Siddhesh
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 473 bytes
Desc: not available
URL: <http://sourceware.org/pipermail/libc-alpha/attachments/20141105/6d2c86b2/attachment.sig>


More information about the Libc-alpha mailing list