bloblist: fix a potential negative size for memmove
It causes a panic when blob is shrunk and 'new_alloced' is less than
'next_ofs'. The data area that needs to be moved should end up at
'hdr->used_size'.
Fixes: 1fe5937549 ("bloblist: Support resizing a blob")
Signed-off-by: Raymond Mao <raymond.mao@linaro.org>
Reviewed-by: Tom Rini <trini@konsulko.com>
Tested-by: Michal Simek <michal.simek@amd.com>
This commit is contained in:
+1
-1
@@ -335,7 +335,7 @@ static int bloblist_resize_rec(struct bloblist_hdr *hdr,
|
||||
next_ofs = bloblist_blob_end_ofs(hdr, rec);
|
||||
if (next_ofs != hdr->used_size) {
|
||||
memmove((void *)hdr + next_ofs + expand_by,
|
||||
(void *)hdr + next_ofs, new_alloced - next_ofs);
|
||||
(void *)hdr + next_ofs, hdr->used_size - next_ofs);
|
||||
}
|
||||
hdr->used_size = new_alloced;
|
||||
|
||||
|
||||
Reference in New Issue
Block a user