> -----Original Message-----
> From: Colin King [mailto:colin.k...@canonical.com]
> Sent: Monday, May 15, 2017 8:56 AM
> To: Raghava Aditya Renukunta <raghavaaditya.renuku...@microsemi.com>;
> dl-esc-Aacraid Linux Driver <aacr...@microsemi.com>; James E . J . Bottomley
> <j...@linux.vnet.ibm.com>; Martin K . Petersen
> <martin.peter...@oracle.com>; linux-scsi@vger.kernel.org
> Cc: kernel-janit...@vger.kernel.org; linux-ker...@vger.kernel.org
> Subject: [PATCH] scsi: aacraid: fix leak of data from stack back to userspace
> 
> From: Colin Ian King <colin.k...@canonical.com>
> 
> The fields sense_data_size and sense_data are unitialized garbage from the
> stack and are being copied back to userspace.  Fix this leak of stack 
> information
> by ensuring they are zero'd.
> 
> Detected by CoverityScan, CID#1435473 ("Uninitialized scalar variable")
> 
> Fixes: 423400e64d377 ("scsi: aacraid: Include HBA direct interface")
> Signed-off-by: Colin Ian King <colin.k...@canonical.com>
> ---
>  drivers/scsi/aacraid/commctrl.c | 2 ++
>  1 file changed, 2 insertions(+)
> 
Acked-by: Dave Carroll <david.carr...@microsemi.com>

Reply via email to