On 26.06.2018 07:32, Georgi Guninski wrote: > On Mon, Jun 25, 2018 at 09:27:59AM +0200, Christian Borntraeger wrote: >> - /* Overwrite parameters in the kernel image, which are "rom" */ >> - strcpy(rom_ptr(KERN_PARM_AREA), ipl->cmdline); > >> + strcpy(rom_ptr(KERN_PARM_AREA), ipl->cmdline); > > Why not replace strcpy() with strncpy() or snprintf()? > strcpy() may overflow. This will be fixed by https://lists.gnu.org/archive/html/qemu-devel/2018-06/msg04227.html by adding a check for a valid size. Thomas -- To unsubscribe from this list: send the line "unsubscribe linux-s390" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html