[LTP] [PATCH 1/3] lib: Avoid loop_info.lo_name buffer overflow
Petr Vorel
pvorel@suse.cz
Tue Jul 28 15:58:58 CEST 2026
> From: Andrea Cervesato <andrea.cervesato@suse.com>
> The backing file path may be longer than the fixed-size lo_name field,
> so an unbounded strcpy() can overflow the loop_info structure. Copy at
> most the field size and rely on the preceding memset() for termination.
> Signed-off-by: Andrea Cervesato <andrea.cervesato@suse.com>
> ---
> lib/tst_device.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
> diff --git a/lib/tst_device.c b/lib/tst_device.c
> index d3c53a1a18d2e4948ebff21d6d66c0ccd1590c6f..b5c3ccdb7be52ce600fbd7d7a83f6081df65d616 100644
> --- a/lib/tst_device.c
> +++ b/lib/tst_device.c
> @@ -182,7 +182,7 @@ int tst_attach_device(const char *dev, const char *file)
> * LOOP_SET_FD and LOOP_SET_STATUS.
> */
> memset(&loopinfo, 0, sizeof(loopinfo));
> - strcpy(loopinfo.lo_name, file);
> + strncpy(loopinfo.lo_name, file, sizeof(loopinfo.lo_name) - 1);
Reviewed-by: Petr Vorel <pvorel@suse.cz>
I suppose strncpy() is recommended as safer alternative to strcpy(),
right? Shouldn't we check for strlen(file) is not longer than
sizeof(loopinfo.lo_name) -1 while we are at it?
Kind regards,
Petr
More information about the ltp
mailing list