From: Anssi Hannula Date: Tue, 30 Dec 2014 18:46:11 +0000 (+0200) Subject: pcm: fix buffer overflow in snd_pcm_chmap_print() X-Git-Tag: v1.0.29~13 X-Git-Url: https://git.alsa-project.org/?a=commitdiff_plain;h=b2ed0aa9f28979f125a9db0548cfd38ac2334775;p=alsa-lib.git pcm: fix buffer overflow in snd_pcm_chmap_print() The size argument is wrong for one of the snprintf() calls in snd_pcm_chmap_print(), allowing an overflow to happen (the user-provided buffer may be written data up to 2x its actual size). Seen in an user report here: http://trac.kodi.tv/ticket/15641 Signed-off-by: Anssi Hannula Signed-off-by: Takashi Iwai --- diff --git a/src/pcm/pcm.c b/src/pcm/pcm.c index baa47c73..e74e02fc 100644 --- a/src/pcm/pcm.c +++ b/src/pcm/pcm.c @@ -7621,7 +7621,7 @@ int snd_pcm_chmap_print(const snd_pcm_chmap_t *map, size_t maxlen, char *buf) return -ENOMEM; } if (map->pos[i] & SND_CHMAP_DRIVER_SPEC) - len += snprintf(buf + len, maxlen, "%d", p); + len += snprintf(buf + len, maxlen - len, "%d", p); else { const char *name = chmap_names[p]; if (name)