Xi: integer overflow and unvalidated length in (S)ProcXIBarrierReleasePointer
[jcristau: originally this patch fixed the same issue as commit 211e05ac "Xi: Test exact size of XIBarrierReleasePointer", with the addition of these checks] This addresses CVE-2017-12179 Reviewed-by:Alan Coopersmith <alan.coopersmith@oracle.com> Reviewed-by:
Jeremy Huddleston Sequoia <jeremyhu@apple.com> Reviewed-by:
Julien Cristau <jcristau@debian.org> Signed-off-by:
Jeremy Huddleston Sequoia <jeremyhu@apple.com> Signed-off-by:
Nathan Kidd <nkidd@opentext.com> Signed-off-by:
Julien Cristau <jcristau@debian.org> (cherry picked from commit d088e3c1)
Loading
Please register or sign in to comment