bitmap: fix buffer overrun in bitmap init
authorIvan Ilchenko <ivan.ilchenko@oktetlabs.ru>
Wed, 2 Jun 2021 09:49:22 +0000 (12:49 +0300)
committerDavid Marchand <david.marchand@redhat.com>
Fri, 11 Jun 2021 09:03:25 +0000 (11:03 +0200)
Bitmap initialization function is allowed to memset()
caller-provided buffer with number of bytes exceeded
this buffer size. This happens due to wrong comparison
sign between buffer size and number of bytes required
to initialize bitmap.

Fixes: 602c9ca33a4 ("sched: bitmap is now dynamically allocated")
Cc: stable@dpdk.org
Reported-by: Andy Moreton <amoreton@xilinx.com>
Signed-off-by: Ivan Ilchenko <ivan.ilchenko@oktetlabs.ru>
Reviewed-by: Andy Moreton <amoreton@xilinx.com>
Signed-off-by: Andrew Rybchenko <andrew.rybchenko@oktetlabs.ru>
Acked-by: Cristian Dumitrescu <cristian.dumitrescu@intel.com>
lib/eal/include/rte_bitmap.h

index 9e2b8f2..e4623bb 100644 (file)
@@ -185,9 +185,8 @@ rte_bitmap_init(uint32_t n_bits, uint8_t *mem, uint32_t mem_size)
        size = __rte_bitmap_get_memory_footprint(n_bits,
                &array1_byte_offset, &array1_slabs,
                &array2_byte_offset, &array2_slabs);
-       if (size < mem_size) {
+       if (size > mem_size)
                return NULL;
-       }
 
        /* Setup bitmap */
        memset(mem, 0, size);