diff options
author | Dan Carpenter <dan.carpenter@oracle.com> | 2012-04-19 03:00:19 -0400 |
---|---|---|
committer | Greg Kroah-Hartman <gregkh@linuxfoundation.org> | 2012-04-27 12:51:21 -0400 |
commit | d76556549e7a97c25269644afd0b1b18a6c42214 (patch) | |
tree | c0f87cf2070154aa55391407385bb63a4ca659bc /drivers/net | |
parent | 0958c122f47f4ef2a1ae552fed56a8bf8502c32b (diff) |
ksz884x: don't copy too much in netdev_set_mac_address()
[ Upstream commit 716af4abd6e6370226f567af50bfaca274515980 ]
MAX_ADDR_LEN is 32. ETH_ALEN is 6. mac->sa_data is a 14 byte array, so
the memcpy() is doing a read past the end of the array. I asked about
this on netdev and Ben Hutchings told me it's supposed to be copying
ETH_ALEN bytes (thanks Ben).
Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Diffstat (limited to 'drivers/net')
-rw-r--r-- | drivers/net/ksz884x.c | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/drivers/net/ksz884x.c b/drivers/net/ksz884x.c index 41ea5920c15..95b6664e936 100644 --- a/drivers/net/ksz884x.c +++ b/drivers/net/ksz884x.c | |||
@@ -5679,7 +5679,7 @@ static int netdev_set_mac_address(struct net_device *dev, void *addr) | |||
5679 | memcpy(hw->override_addr, mac->sa_data, MAC_ADDR_LEN); | 5679 | memcpy(hw->override_addr, mac->sa_data, MAC_ADDR_LEN); |
5680 | } | 5680 | } |
5681 | 5681 | ||
5682 | memcpy(dev->dev_addr, mac->sa_data, MAX_ADDR_LEN); | 5682 | memcpy(dev->dev_addr, mac->sa_data, ETH_ALEN); |
5683 | 5683 | ||
5684 | interrupt = hw_block_intr(hw); | 5684 | interrupt = hw_block_intr(hw); |
5685 | 5685 | ||