[PATCH] IPC: access to unmapped vmalloc area in grow_ary()
authorAlexey Kuznetsov <kuznet@ms2.inr.ac.ru>
Mon, 17 Apr 2006 11:39:23 +0000 (15:39 +0400)
committerLinus Torvalds <torvalds@g5.osdl.org>
Tue, 18 Apr 2006 01:40:40 +0000 (18:40 -0700)
commita9a5cd5d2a57fb76dbae2115450f777b69beccf7
tree510318d8bebb35bb2e1bdaeb7dba0baf9bb073cd
parent69cf0fac6052c5bd3fb3469a41d4216e926028f8
[PATCH] IPC: access to unmapped vmalloc area in grow_ary()

grow_ary() should not copy struct ipc_id_ary (it copies new->p, not
new). Due to this, memcpy() src pointer could hit unmapped vmalloc page
when near page boundary.

Found during OpenVZ stress testing

Signed-off-by: Alexey Kuznetsov <kuznet@ms2.inr.ac.ru>
Signed-off-by: Kirill Korotaev <dev@openvz.org>
Signed-off-by: Linus Torvalds <torvalds@osdl.org>
ipc/util.c