We never initialize "msgp". It's unfortunate that GCC doesn't warn about this. Signed-off-by: Dan Carpenter <dan.carpenter@xxxxxxxxxx> diff --git a/ipc/compat.c b/ipc/compat.c index 6da376b..0c2ebd0 100644 --- a/ipc/compat.c +++ b/ipc/compat.c @@ -363,7 +363,7 @@ static long compat_do_msg_steal(void __user *dest, struct msg_msg *msg, size_t b long compat_do_msg_fill(void __user *dest, struct msg_msg *msg, size_t bufsz) { - struct compat_msgbuf __user *msgp; + struct compat_msgbuf __user *msgp = dest; size_t msgsz; if (put_user(msg->m_type, &msgp->mtype)) -- To unsubscribe from this list: send the line "unsubscribe kernel-janitors" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html