[LTP] [PATCH 1/3] lib: Avoid loop_info.lo_name buffer overflow

Andrea Cervesato andrea.cervesato@suse.de
Fri Jul 17 14:33:18 CEST 2026


From: Andrea Cervesato <andrea.cervesato@suse.com>

The backing file path may be longer than the fixed-size lo_name field,
so an unbounded strcpy() can overflow the loop_info structure. Copy at
most the field size and rely on the preceding memset() for termination.

Signed-off-by: Andrea Cervesato <andrea.cervesato@suse.com>
---
 lib/tst_device.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/lib/tst_device.c b/lib/tst_device.c
index d3c53a1a18d2e4948ebff21d6d66c0ccd1590c6f..b5c3ccdb7be52ce600fbd7d7a83f6081df65d616 100644
--- a/lib/tst_device.c
+++ b/lib/tst_device.c
@@ -182,7 +182,7 @@ int tst_attach_device(const char *dev, const char *file)
 	 * LOOP_SET_FD and LOOP_SET_STATUS.
 	 */
 	memset(&loopinfo, 0, sizeof(loopinfo));
-	strcpy(loopinfo.lo_name, file);
+	strncpy(loopinfo.lo_name, file, sizeof(loopinfo.lo_name) - 1);
 
 	if (ioctl(dev_fd, LOOP_SET_STATUS, &loopinfo)) {
 		close(dev_fd);

-- 
2.51.0



More information about the ltp mailing list