From 24ded86e8dd528b056d73630ff33e526f9540dbc Mon Sep 17 00:00:00 2001 From: Matthew Ahrens Date: Thu, 4 Aug 2016 16:16:29 -0700 Subject: [PATCH] OpenZFS 7261 - nvlist code should enforce name length limit Authored by: Matthew Ahrens Reviewed by: Sebastien Roy Reviewed by: George Wilson Reviewed by: Robert Mustacchi Approved by: Dan McDonald Reviewed-by: Don Brady Reviewed-by: George Melikov Reviewed-by: Brian Behlendorf Ported-by: Giuseppe Di Natale OpenZFS-issue: https://www.illumos.org/issues/7261 OpenZFS-commit: https://github.com/openzfs/openzfs/commit/48dd5e6 Closes #6579 --- module/nvpair/nvpair.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/module/nvpair/nvpair.c b/module/nvpair/nvpair.c index 8e654053cb..dffb226a23 100644 --- a/module/nvpair/nvpair.c +++ b/module/nvpair/nvpair.c @@ -916,6 +916,8 @@ nvlist_add_common(nvlist_t *nvl, const char *name, /* calculate sizes of the nvpair elements and the nvpair itself */ name_sz = strlen(name) + 1; + if (name_sz >= 1ULL << (sizeof (nvp->nvp_name_sz) * NBBY - 1)) + return (EINVAL); nvp_sz = NVP_SIZE_CALC(name_sz, value_sz);