diff options
author | Bradley Grove <bgrove@attotech.com> | 2013-08-29 15:55:42 -0400 |
---|---|---|
committer | James Bottomley <JBottomley@Parallels.com> | 2013-09-06 14:13:52 -0400 |
commit | eaf74a06f13aa0e4e7e2024cb6db2ccedd3d32e3 (patch) | |
tree | 66b213fb03b005c9ba763573f809f0d20be97dd8 | |
parent | 64d29bd83ef36911001afc3d1f21404106739ce1 (diff) |
[SCSI] esas2r: smatch - Fix overrun due to sprintf appending NULL
Reported-by: Dan Carpenter <dan.carpenter@oracle.com>
Signed-off-by: Bradley Grove <bgrove@attotech.com>
Signed-off-by: James Bottomley <JBottomley@Parallels.com>
-rw-r--r-- | drivers/scsi/esas2r/esas2r_vda.c | 7 |
1 files changed, 5 insertions, 2 deletions
diff --git a/drivers/scsi/esas2r/esas2r_vda.c b/drivers/scsi/esas2r/esas2r_vda.c index f8ec6d636846..fd1392879647 100644 --- a/drivers/scsi/esas2r/esas2r_vda.c +++ b/drivers/scsi/esas2r/esas2r_vda.c | |||
@@ -302,6 +302,7 @@ static void esas2r_complete_vda_ioctl(struct esas2r_adapter *a, | |||
302 | if (vi->cmd.cfg.cfg_func == VDA_CFG_GET_INIT) { | 302 | if (vi->cmd.cfg.cfg_func == VDA_CFG_GET_INIT) { |
303 | struct atto_ioctl_vda_cfg_cmd *cfg = &vi->cmd.cfg; | 303 | struct atto_ioctl_vda_cfg_cmd *cfg = &vi->cmd.cfg; |
304 | struct atto_vda_cfg_rsp *rsp = &rq->func_rsp.cfg_rsp; | 304 | struct atto_vda_cfg_rsp *rsp = &rq->func_rsp.cfg_rsp; |
305 | char buf[sizeof(cfg->data.init.fw_release) + 1]; | ||
305 | 306 | ||
306 | cfg->data_length = | 307 | cfg->data_length = |
307 | cpu_to_le32(sizeof(struct atto_vda_cfg_init)); | 308 | cpu_to_le32(sizeof(struct atto_vda_cfg_init)); |
@@ -309,11 +310,13 @@ static void esas2r_complete_vda_ioctl(struct esas2r_adapter *a, | |||
309 | le32_to_cpu(rsp->vda_version); | 310 | le32_to_cpu(rsp->vda_version); |
310 | cfg->data.init.fw_build = rsp->fw_build; | 311 | cfg->data.init.fw_build = rsp->fw_build; |
311 | 312 | ||
312 | sprintf((char *)&cfg->data.init.fw_release, | 313 | snprintf(buf, sizeof(buf), "%1d.%02d", |
313 | "%1d.%02d", | ||
314 | (int)LOBYTE(le16_to_cpu(rsp->fw_release)), | 314 | (int)LOBYTE(le16_to_cpu(rsp->fw_release)), |
315 | (int)HIBYTE(le16_to_cpu(rsp->fw_release))); | 315 | (int)HIBYTE(le16_to_cpu(rsp->fw_release))); |
316 | 316 | ||
317 | memcpy(&cfg->data.init.fw_release, buf, | ||
318 | sizeof(cfg->data.init.fw_release)); | ||
319 | |||
317 | if (LOWORD(LOBYTE(cfg->data.init.fw_build)) == 'A') | 320 | if (LOWORD(LOBYTE(cfg->data.init.fw_build)) == 'A') |
318 | cfg->data.init.fw_version = | 321 | cfg->data.init.fw_version = |
319 | cfg->data.init.fw_build; | 322 | cfg->data.init.fw_build; |