aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorBradley Grove <bgrove@attotech.com>2013-08-29 15:55:42 -0400
committerJames Bottomley <JBottomley@Parallels.com>2013-09-06 14:13:52 -0400
commiteaf74a06f13aa0e4e7e2024cb6db2ccedd3d32e3 (patch)
tree66b213fb03b005c9ba763573f809f0d20be97dd8
parent64d29bd83ef36911001afc3d1f21404106739ce1 (diff)
[SCSI] esas2r: smatch - Fix overrun due to sprintf appending NULL
Reported-by: Dan Carpenter <dan.carpenter@oracle.com> Signed-off-by: Bradley Grove <bgrove@attotech.com> Signed-off-by: James Bottomley <JBottomley@Parallels.com>
-rw-r--r--drivers/scsi/esas2r/esas2r_vda.c7
1 files changed, 5 insertions, 2 deletions
diff --git a/drivers/scsi/esas2r/esas2r_vda.c b/drivers/scsi/esas2r/esas2r_vda.c
index f8ec6d636846..fd1392879647 100644
--- a/drivers/scsi/esas2r/esas2r_vda.c
+++ b/drivers/scsi/esas2r/esas2r_vda.c
@@ -302,6 +302,7 @@ static void esas2r_complete_vda_ioctl(struct esas2r_adapter *a,
302 if (vi->cmd.cfg.cfg_func == VDA_CFG_GET_INIT) { 302 if (vi->cmd.cfg.cfg_func == VDA_CFG_GET_INIT) {
303 struct atto_ioctl_vda_cfg_cmd *cfg = &vi->cmd.cfg; 303 struct atto_ioctl_vda_cfg_cmd *cfg = &vi->cmd.cfg;
304 struct atto_vda_cfg_rsp *rsp = &rq->func_rsp.cfg_rsp; 304 struct atto_vda_cfg_rsp *rsp = &rq->func_rsp.cfg_rsp;
305 char buf[sizeof(cfg->data.init.fw_release) + 1];
305 306
306 cfg->data_length = 307 cfg->data_length =
307 cpu_to_le32(sizeof(struct atto_vda_cfg_init)); 308 cpu_to_le32(sizeof(struct atto_vda_cfg_init));
@@ -309,11 +310,13 @@ static void esas2r_complete_vda_ioctl(struct esas2r_adapter *a,
309 le32_to_cpu(rsp->vda_version); 310 le32_to_cpu(rsp->vda_version);
310 cfg->data.init.fw_build = rsp->fw_build; 311 cfg->data.init.fw_build = rsp->fw_build;
311 312
312 sprintf((char *)&cfg->data.init.fw_release, 313 snprintf(buf, sizeof(buf), "%1d.%02d",
313 "%1d.%02d",
314 (int)LOBYTE(le16_to_cpu(rsp->fw_release)), 314 (int)LOBYTE(le16_to_cpu(rsp->fw_release)),
315 (int)HIBYTE(le16_to_cpu(rsp->fw_release))); 315 (int)HIBYTE(le16_to_cpu(rsp->fw_release)));
316 316
317 memcpy(&cfg->data.init.fw_release, buf,
318 sizeof(cfg->data.init.fw_release));
319
317 if (LOWORD(LOBYTE(cfg->data.init.fw_build)) == 'A') 320 if (LOWORD(LOBYTE(cfg->data.init.fw_build)) == 'A')
318 cfg->data.init.fw_version = 321 cfg->data.init.fw_version =
319 cfg->data.init.fw_build; 322 cfg->data.init.fw_build;