[git commit] pstree: fix theoretically unsafe code

Denys Vlasenko vda.linux at googlemail.com
Thu Jun 27 23:59:25 UTC 2013


commit: http://git.busybox.net/busybox/commit/?id=173aa78bcf68c2a036823bdee803b35820ddcd44
branch: http://git.busybox.net/busybox/commit/?id=refs/heads/master

In practice, p->comm is never long enough to trigger the bug, but still.

Signed-off-by: Denys Vlasenko <vda.linux at googlemail.com>
---
 procps/pstree.c |    2 +-
 1 files changed, 1 insertions(+), 1 deletions(-)

diff --git a/procps/pstree.c b/procps/pstree.c
index ea690a9..ed1a412 100644
--- a/procps/pstree.c
+++ b/procps/pstree.c
@@ -349,7 +349,7 @@ static void dump_by_user(PROC *current, uid_t uid)
 static void handle_thread(const char *comm, pid_t pid, pid_t ppid, uid_t uid)
 {
 	char threadname[COMM_DISP_LEN + 1];
-	sprintf(threadname, "{%.*s}", (int)sizeof(threadname) - 1, comm);
+	sprintf(threadname, "{%.*s}", (int)sizeof(threadname) - 3, comm);
 	add_proc(threadname, pid, ppid, uid/*, 1*/);
 }
 #endif


More information about the busybox-cvs mailing list