[LTP] [PATCH 1/3] lib: Avoid loop_info.lo_name buffer overflow

Petr Vorel pvorel@suse.cz
Tue Jul 28 15:58:58 CEST 2026


> From: Andrea Cervesato <andrea.cervesato@suse.com>

> The backing file path may be longer than the fixed-size lo_name field,
> so an unbounded strcpy() can overflow the loop_info structure. Copy at
> most the field size and rely on the preceding memset() for termination.

> Signed-off-by: Andrea Cervesato <andrea.cervesato@suse.com>
> ---
>  lib/tst_device.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)

> diff --git a/lib/tst_device.c b/lib/tst_device.c
> index d3c53a1a18d2e4948ebff21d6d66c0ccd1590c6f..b5c3ccdb7be52ce600fbd7d7a83f6081df65d616 100644
> --- a/lib/tst_device.c
> +++ b/lib/tst_device.c
> @@ -182,7 +182,7 @@ int tst_attach_device(const char *dev, const char *file)
>  	 * LOOP_SET_FD and LOOP_SET_STATUS.
>  	 */
>  	memset(&loopinfo, 0, sizeof(loopinfo));
> -	strcpy(loopinfo.lo_name, file);
> +	strncpy(loopinfo.lo_name, file, sizeof(loopinfo.lo_name) - 1);

Reviewed-by: Petr Vorel <pvorel@suse.cz>

I suppose strncpy() is recommended as safer alternative to strcpy(),
right? Shouldn't we check for strlen(file) is not longer than
sizeof(loopinfo.lo_name) -1 while we are at it?

Kind regards,
Petr


More information about the ltp mailing list