Defined in 1 files as a function:
Referenced in 28 files:
- crypto/af_alg.c
- crypto/algif_rng.c, line 156
- drivers/net/ppp/pppoe.c, line 816
- net/can/bcm.c
- net/can/isotp.c, line 1197
- net/can/j1939/socket.c, line 910
- net/can/raw.c, line 973
- net/ieee802154/socket.c
- net/ipv4/ping.c, line 667
- net/ipv4/raw.c
- net/ipv6/raw.c
- net/key/af_key.c, line 3713
- net/l2tp/l2tp_ip.c, line 479
- net/l2tp/l2tp_ppp.c, line 296
- net/llc/af_llc.c, line 981
- net/mctp/af_mctp.c, line 263
- net/netlink/af_netlink.c, line 1885
- net/nfc/llcp_commands.c
- net/nfc/rawsock.c, line 235
- net/packet/af_packet.c, line 2045
- net/phonet/datagram.c, line 95
- net/phonet/pep.c, line 1193
- net/qrtr/af_qrtr.c, line 969
- net/sctp/sm_make_chunk.c, line 1019
- net/smc/smc_tx.c, line 249
- net/vmw_vsock/hyperv_transport.c, line 676
- net/vmw_vsock/vmci_transport.c, line 1722
- net/x25/af_x25.c, line 1191
Smatch caller information:
net/can/raw.c raw_sendmsg() -> memcpy_from_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | data | 4096-ptr_max |
| PARAM_VALUE | 1 | msg | 4096-ptr_max |
| PARAM_VALUE | 1 | msg->msg_name | 0,4096-ptr_max |
| PARAM_VALUE | 2 | len | 13-2060 |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16,24,36-s32max |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,28,128 |
| BUF_SIZE | 1 | msg->msg_ubuf | (-1),16 |
| DATA_SOURCE | 1 | msg | $1 |
| DATA_SOURCE | 2 | len | $2 |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_controllen | 0-s32max[c] |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 1-18446744073709551614 |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | msg->msg_namelen | 0-128 |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | 13-2060 |
| UNITS | 2 | len | unit_byte |
| USER_PTR | 1 | msg->msg_control | |
| USER_PTR | 1 | msg->msg_name | |
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk |
net/phonet/datagram.c pn_sendmsg() -> memcpy_from_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | data | 4096-ptr_max |
| PARAM_VALUE | 1 | msg | 4096-ptr_max |
| PARAM_VALUE | 1 | msg->msg_name | 4096-ptr_max |
| PARAM_VALUE | 1 | msg->msg_namelen | s32min-(-1),16-s32max |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16,24,36-s32max |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,28,128 |
| BUF_SIZE | 1 | msg->msg_ubuf | (-1),16 |
| DATA_SOURCE | 1 | msg | $1 |
| DATA_SOURCE | 2 | len | $2 |
| FUZZY_MAX | 1 | msg->msg_namelen | 16 |
| BIT_INFO | 1 | msg->msg_flags | 0x0,0x800040c0 |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_controllen | 0-s32max[c] |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 1-18446744073709551614 |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | msg->msg_namelen | 16-128 |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | s32min-s32max |
| UNITS | 2 | len | unit_byte |
| USER_PTR | 1 | msg->msg_control | |
| USER_PTR | 1 | msg->msg_name | |
| HALF_LOCKED2 | &vq->mutex |
net/key/af_key.c pfkey_sendmsg() -> memcpy_from_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | data | 4096-ptr_max |
| PARAM_VALUE | 1 | msg | 4096-ptr_max |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16,24,36-s32max |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,28,128 |
| BUF_SIZE | 1 | msg->msg_ubuf | (-1),16 |
| CAPPED_DATA | 2 | len | 1 |
| DATA_SOURCE | 1 | msg | $1 |
| DATA_SOURCE | 2 | len | $2 |
| BIT_INFO | 1 | msg->msg_flags | 0x0,0xfffffffe |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_controllen | 0-s32max[c] |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 1-18446744073709551614 |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | msg->msg_namelen | 0-128 |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | 1-s32max[c] |
| UNITS | 2 | len | unit_byte |
| USER_PTR | 1 | msg->msg_control | |
| USER_PTR | 1 | msg->msg_name | |
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk |
net/ipv4/ping.c ping_common_sendmsg() -> memcpy_from_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | data | 1575305641890148352,3001101085870116864 |
| PARAM_VALUE | 1 | msg | 4096-ptr_max |
| PARAM_VALUE | 2 | len | 8 |
| BUF_SIZE | 0 | data | 8 |
| BUF_SIZE | 0 | data | 8 |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16,24,36-s32max |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,28,128 |
| BUF_SIZE | 1 | msg->msg_ubuf | (-1),16 |
| DATA_SOURCE | 0 | data | $3 |
| DATA_SOURCE | 1 | msg | $1 |
| DATA_SOURCE | 2 | len | $4 |
| BIT_INFO | 1 | msg->msg_flags | 0x0,0xfffffffe |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_controllen | 0-s32max[c] |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 1-18446744073709551614 |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | msg->msg_namelen | 0-128 |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| UNITS | 2 | len | unit_byte |
| USER_PTR | 1 | msg->msg_control | |
| USER_PTR | 1 | msg->msg_name | |
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk |
net/qrtr/af_qrtr.c qrtr_sendmsg() -> memcpy_from_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | data | 4096-ptr_max |
| PARAM_VALUE | 1 | msg | 4096-ptr_max |
| PARAM_VALUE | 1 | msg->msg_flags | 0-126 |
| PARAM_VALUE | 1 | msg->msg_name | 0,4096-ptr_max |
| PARAM_VALUE | 2 | len | 0-u16max |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16,24,36-s32max |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,28,128 |
| BUF_SIZE | 1 | msg->msg_ubuf | (-1),16 |
| DATA_SOURCE | 1 | msg | $1 |
| DATA_SOURCE | 2 | len | $2 |
| BIT_INFO | 1 | msg->msg_flags | 0x0,0x40 |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_controllen | 0-s32max[c] |
| USER_DATA | 1 | msg->msg_flags | 0-126[c] |
| USER_DATA | 1 | msg->msg_iter.count | 1-18446744073709551614 |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | msg->msg_namelen | 0-128 |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | 0-u16max |
| USER_PTR | 1 | msg->msg_control | |
| USER_PTR | 1 | msg->msg_name | |
| LOCK2 | sk | ||
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk |
net/nfc/rawsock.c rawsock_sendmsg() -> memcpy_from_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | data | 4096-ptr_max |
| PARAM_VALUE | 1 | msg | 4096-ptr_max |
| PARAM_VALUE | 1 | msg->msg_namelen | 0 |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16,24,36-s32max |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,28,128 |
| BUF_SIZE | 1 | msg->msg_ubuf | (-1),16 |
| DATA_SOURCE | 1 | msg | $1 |
| DATA_SOURCE | 2 | len | $2 |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_controllen | 0-s32max[c] |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 1-18446744073709551614 |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | msg->msg_namelen | 0 |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | s32min-s32max |
| UNITS | 2 | len | unit_byte |
| USER_PTR | 1 | msg->msg_control | |
| USER_PTR | 1 | msg->msg_name | |
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk |
net/packet/af_packet.c packet_sendmsg_spkt() -> memcpy_from_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | data | 4096-ptr_max |
| PARAM_VALUE | 1 | msg | 4096-ptr_max |
| PARAM_VALUE | 1 | msg->msg_name | 4096-ptr_max |
| PARAM_VALUE | 1 | msg->msg_namelen | s32min-(-1),16-s32max |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16,24,36-s32max |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,28,128 |
| BUF_SIZE | 1 | msg->msg_ubuf | (-1),16 |
| CAPPED_DATA | 2 | len | 1 |
| DATA_SOURCE | 1 | msg | $1 |
| DATA_SOURCE | 2 | len | $2 |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_controllen | 0-s32max[c] |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 1-18446744073709551614 |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | msg->msg_namelen | 16-17,19-128 |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | 1-s32max[c] |
| UNITS | 2 | len | unit_byte |
| USER_PTR | 1 | msg->msg_control | |
| USER_PTR | 1 | msg->msg_name | |
| HALF_LOCKED2 | sk |
net/phonet/pep.c pep_sendmsg() -> memcpy_from_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | data | 4096-ptr_max |
| PARAM_VALUE | 1 | msg | 4096-ptr_max |
| PARAM_VALUE | 1 | msg->msg_flags | 128-u32max |
| PARAM_VALUE | 2 | len | 0-u16max |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16,24,36-s32max |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,28,128 |
| BUF_SIZE | 1 | msg->msg_ubuf | (-1),16 |
| DATA_SOURCE | 1 | msg | $1 |
| DATA_SOURCE | 2 | len | $2 |
| BIT_INFO | 1 | msg->msg_flags | 0x80,0x800040c0 |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_controllen | 0-s32max[c] |
| USER_DATA | 1 | msg->msg_flags | 128-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 1-18446744073709551614 |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | msg->msg_namelen | 0-128 |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | 0-u16max |
| UNITS | 2 | len | unit_byte |
| USER_PTR | 1 | msg->msg_control | |
| USER_PTR | 1 | msg->msg_name | |
| HALF_LOCKED2 | &vq->mutex |
net/ipv4/raw.c raw_probe_proto_opt() -> memcpy_from_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 1 | msg | 4096-ptr_max |
| PARAM_VALUE | 2 | len | 2 |
| BUF_SIZE | 0 | data | 1 |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk |
net/ipv4/raw.c raw_send_hdrinc() -> memcpy_from_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | data | 4096-ptr_max |
| PARAM_VALUE | 1 | msg | 4096-ptr_max |
| PARAM_VALUE | 1 | msg->msg_controllen | 0 |
| PARAM_VALUE | 1 | msg->msg_namelen | s32min-0,16-s32max |
| PARAM_VALUE | 2 | len | 20-u16max |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16,24,36-s32max |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,28,128 |
| BUF_SIZE | 1 | msg->msg_ubuf | (-1),16 |
| CAPPED_DATA | 2 | len | 1 |
| DATA_SOURCE | 0 | data | r ip_hdr |
| DATA_SOURCE | 1 | msg | $2 |
| DATA_SOURCE | 2 | len | $3 |
| FUZZY_MAX | 1 | msg->msg_namelen | 16 |
| BIT_INFO | 1 | msg->msg_flags | 0x0,0xfffffffe |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_controllen | 0[c] |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 1-18446744073709551614 |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | msg->msg_namelen | 0,16-128 |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | 21-u16max[c] |
| UNITS | 2 | len | unit_byte |
| USER_PTR | 1 | msg->msg_control | |
| USER_PTR | 1 | msg->msg_name | |
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk |
net/sctp/sm_make_chunk.c sctp_make_abort_user() -> memcpy_from_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | data | 4096-ptr_max |
| PARAM_VALUE | 1 | msg | 4096-ptr_max |
| PARAM_VALUE | 2 | len | 1-4000000 |
| BUF_SIZE | 0 | data | 1-u64max |
| BUF_SIZE | 0 | data | 1-u64max |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16,24,36-s32max |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,28,128 |
| BUF_SIZE | 1 | msg->msg_ubuf | (-1),16 |
| CAPPED_DATA | 2 | len | 1 |
| DATA_SOURCE | 0 | data | r _kmalloc_noprof |
| DATA_SOURCE | 1 | msg | $1 |
| DATA_SOURCE | 2 | len | $2 |
| NOSPEC | 1 | msg->msg_iter.count | |
| NOSPEC | 2 | len | |
| NOSPEC | 2 | len | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_controllen | 0-s32max[c] |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | msg->msg_namelen | 0-128 |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | 2-4000000[c] |
| UNITS | 2 | len | unit_byte |
| BYTE_COUNT | 0 | ==data2 | 8050 |
| USER_PTR | 1 | msg->msg_control | |
| USER_PTR | 1 | msg->msg_name | |
| LOCK2 | sk | ||
| HALF_LOCKED2 | &vq->mutex |
net/llc/af_llc.c llc_ui_sendmsg() -> memcpy_from_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | data | 4096-ptr_max |
| PARAM_VALUE | 1 | msg | 4096-ptr_max |
| PARAM_VALUE | 2 | len | 0-s32max |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16,24,36-s32max |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,28,128 |
| BUF_SIZE | 1 | msg->msg_ubuf | (-1),16 |
| DATA_SOURCE | 1 | msg | $1 |
| FUZZY_MAX | 2 | len | 0 |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_controllen | 0-s32max[c] |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 1-18446744073709551614 |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | msg->msg_namelen | 0-128 |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| UNITS | 2 | len | unit_byte |
| USER_PTR | 1 | msg->msg_control | |
| USER_PTR | 1 | msg->msg_name | |
| LOCK2 | sk | ||
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk |
net/smc/smc_tx.c smc_tx_sendmsg() -> memcpy_from_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | data | 4096-ptr_max |
| PARAM_VALUE | 0 | *data | 0-255 |
| PARAM_VALUE | 1 | msg | 4096-ptr_max |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16,24,36-s32max |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,28,128 |
| BUF_SIZE | 1 | msg->msg_ubuf | (-1),16 |
| DATA_SOURCE | 1 | msg | $1 |
| BIT_INFO | 1 | msg->msg_flags | 0x0,0xdfffffff |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_controllen | 0-s32max[c] |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 1-18446744073709551614 |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | msg->msg_namelen | 0-128 |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | (-2147483647)-s32max |
| UNITS | 0 | data | unit_byte |
| UNITS | 2 | len | unit_byte |
| USER_PTR | 1 | msg->msg_control | |
| USER_PTR | 1 | msg->msg_name | |
| LOCK2 | sk | ||
| HALF_LOCKED2 | &vq->mutex |
net/l2tp/l2tp_ip.c l2tp_ip_sendmsg() -> memcpy_from_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | data | 4096-ptr_max |
| PARAM_VALUE | 1 | msg | 4096-ptr_max |
| PARAM_VALUE | 1 | msg->msg_name | 0,4096-ptr_max |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16,24,36-s32max |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,28,128 |
| BUF_SIZE | 1 | msg->msg_ubuf | (-1),16 |
| DATA_SOURCE | 1 | msg | $1 |
| DATA_SOURCE | 2 | len | $2 |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_controllen | 0-s32max[c] |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 1-18446744073709551614 |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | msg->msg_namelen | 0-128 |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | s32min-s32max |
| UNITS | 2 | len | unit_byte |
| USER_PTR | 1 | msg->msg_control | |
| USER_PTR | 1 | msg->msg_name | |
| LOCK2 | sk | ||
| HALF_LOCKED2 | &vq->mutex |
net/vmw_vsock/hyperv_transport.c hvs_stream_enqueue() -> memcpy_from_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 1 | msg | 4096-ptr_max |
| PARAM_VALUE | 1 | msg->msg_namelen | 0 |
| PARAM_VALUE | 2 | len | 1-4088 |
| BUF_SIZE | 0 | data | 4088 |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16,24,36-s32max |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,28,128 |
| BUF_SIZE | 1 | msg->msg_ubuf | (-1),16 |
| CAPPED_DATA | 2 | len | 1 |
| DATA_SOURCE | 1 | msg | $1 |
| BIT_INFO | 1 | msg->msg_flags | 0x0,0xfffffffe |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_controllen | 0-s32max[c] |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | msg->msg_namelen | 0 |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | 1-4087[c] |
| UNITS | 2 | len | unit_byte |
| USER_PTR | 1 | msg->msg_control | |
| USER_PTR | 1 | msg->msg_name | |
| LOCK2 | sk | ||
| HALF_LOCKED2 | &vq->mutex |
net/can/bcm.c bcm_rx_setup() -> memcpy_from_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | data | 16,4096-ptr_max |
| PARAM_VALUE | 1 | msg | 4096-ptr_max |
| PARAM_VALUE | 1 | msg->msg_iter.folioq | 1-u64max |
| PARAM_VALUE | 1 | msg->msg_iter.kvec | 4096-u64max |
| PARAM_VALUE | 2 | len | 0-4000000 |
| BUF_SIZE | 0 | data | 0-u32max |
| BUF_SIZE | 0 | data | 0-u32max |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16,24,36-s32max |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,28,128 |
| BUF_SIZE | 1 | msg->msg_ubuf | (-1),16 |
| DATA_SOURCE | 0 | data | r _kmalloc_noprof |
| DATA_SOURCE | 1 | msg | $1 |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_controllen | 0-s32max[c] |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 1-18446744073709551614 |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | msg->msg_namelen | 0-128 |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_PTR | 1 | msg->msg_control | |
| USER_PTR | 1 | msg->msg_name | |
| LOCK2 | sk | ||
| HALF_LOCKED2 | &vq->mutex |
net/can/bcm.c bcm_rx_setup() -> memcpy_from_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | data | 16,4096-ptr_max |
| PARAM_VALUE | 1 | msg | 4096-ptr_max |
| PARAM_VALUE | 1 | msg->msg_iter.folioq | 1-u64max |
| PARAM_VALUE | 1 | msg->msg_iter.kvec | 4096-u64max |
| PARAM_VALUE | 2 | len | 16-18504 |
| BUF_SIZE | 0 | data | 16,72 |
| BUF_SIZE | 0 | data | 16,72 |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16,24,36-s32max |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,28,128 |
| BUF_SIZE | 1 | msg->msg_ubuf | (-1),16 |
| DATA_SOURCE | 1 | msg | $1 |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_controllen | 0-s32max[c] |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 1-18446744073709551614 |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | msg->msg_namelen | 0-128 |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_PTR | 1 | msg->msg_control | |
| USER_PTR | 1 | msg->msg_name | |
| LOCK2 | sk | ||
| HALF_LOCKED2 | &vq->mutex |
net/can/bcm.c bcm_sendmsg() -> memcpy_from_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | data | 7451157088997707776 |
| PARAM_VALUE | 1 | msg | 4096-ptr_max |
| PARAM_VALUE | 2 | len | 56 |
| BUF_SIZE | 0 | data | 56 |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16,24,36-s32max |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,28,128 |
| BUF_SIZE | 1 | msg->msg_ubuf | (-1),16 |
| DATA_SOURCE | 1 | msg | $1 |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_controllen | 0-s32max[c] |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 1-18446744073709551614 |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | msg->msg_namelen | 0-128 |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| UNITS | 2 | len | unit_byte |
| USER_PTR | 1 | msg->msg_control | |
| USER_PTR | 1 | msg->msg_name | |
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk |
net/can/bcm.c bcm_tx_send() -> memcpy_from_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | data | 4096-ptr_max |
| PARAM_VALUE | 1 | msg | 4096-ptr_max |
| PARAM_VALUE | 1 | msg->msg_iter.folioq | 1-u64max |
| PARAM_VALUE | 1 | msg->msg_iter.kvec | 4096-u64max |
| PARAM_VALUE | 2 | len | 16,72 |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16,24,36-s32max |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,28,128 |
| BUF_SIZE | 1 | msg->msg_ubuf | (-1),16 |
| DATA_SOURCE | 1 | msg | $0 |
| DATA_SOURCE | 2 | len | $3 |
| FUZZY_MAX | 2 | len | 72 |
| BIT_INFO | 2 | len | 0x0,0x58 |
| NOSPEC | 1 | msg->msg_iter.count | |
| HARD_MAX | 2 | len | 72 |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_controllen | 0-s32max[c] |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 1-18446744073709551614 |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | msg->msg_namelen | 0-128 |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| UNITS | 2 | len | unit_byte |
| USER_PTR | 1 | msg->msg_control | |
| USER_PTR | 1 | msg->msg_name | |
| LOCK2 | sk | ||
| HALF_LOCKED2 | &vq->mutex |
net/can/bcm.c bcm_tx_setup() -> memcpy_from_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | data | 4096-ptr_max |
| PARAM_VALUE | 1 | msg | 4096-ptr_max |
| PARAM_VALUE | 1 | msg->msg_iter.folioq | 1-u64max |
| PARAM_VALUE | 1 | msg->msg_iter.kvec | 4096-u64max |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16,24,36-s32max |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,28,128 |
| BUF_SIZE | 1 | msg->msg_ubuf | (-1),16 |
| DATA_SOURCE | 1 | msg | $1 |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_controllen | 0-s32max[c] |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 1-18446744073709551614 |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | msg->msg_namelen | 0-128 |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| UNITS | 2 | len | unit_byte |
| USER_PTR | 1 | msg->msg_control | |
| USER_PTR | 1 | msg->msg_name | |
| LOCK2 | sk | ||
| HALF_LOCKED2 | &vq->mutex |
net/can/bcm.c bcm_tx_setup() -> memcpy_from_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | data | 4096-ptr_max |
| PARAM_VALUE | 1 | msg | 4096-ptr_max |
| PARAM_VALUE | 1 | msg->msg_iter.folioq | 1-u64max |
| PARAM_VALUE | 1 | msg->msg_iter.kvec | 4096-u64max |
| PARAM_VALUE | 2 | len | 16,72 |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16,24,36-s32max |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,28,128 |
| BUF_SIZE | 1 | msg->msg_ubuf | (-1),16 |
| CAPPED_DATA | 2 | len | 1 |
| DATA_SOURCE | 1 | msg | $1 |
| FUZZY_MAX | 2 | len | 72 |
| BIT_INFO | 2 | len | 0x0,0x58 |
| NOSPEC | 1 | msg->msg_iter.count | |
| HARD_MAX | 2 | len | 72 |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_controllen | 0-s32max[c] |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 1-18446744073709551614 |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | msg->msg_namelen | 0-128 |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| NO_OVERFLOW_SIMPLE | 2 | len | |
| UNITS | 2 | len | unit_byte |
| USER_PTR | 1 | msg->msg_control | |
| USER_PTR | 1 | msg->msg_name | |
| LOCK2 | sk | ||
| HALF_LOCKED2 | &vq->mutex |
net/can/isotp.c isotp_sendmsg() -> memcpy_from_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 1 | msg | 4096-ptr_max |
| BUF_SIZE | 0 | data | 1-u32max,u64max |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16,24,36-s32max |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,28,128 |
| BUF_SIZE | 1 | msg->msg_ubuf | (-1),16 |
| CAPPED_DATA | 2 | len | 1 |
| DATA_SOURCE | 1 | msg | $1 |
| DATA_SOURCE | 2 | len | $2 |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_controllen | 0-s32max[c] |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 1-18446744073709551614 |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | msg->msg_namelen | 0-128 |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | 2-s32max[c] |
| UNITS | 2 | len | unit_byte |
| USER_PTR | 1 | msg->msg_control | |
| USER_PTR | 1 | msg->msg_name | |
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk |
crypto/af_alg.c af_alg_sendmsg() -> memcpy_from_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 1 | msg | 4096-ptr_max |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16,24,36-s32max |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,28,128 |
| BUF_SIZE | 1 | msg->msg_ubuf | (-1),16 |
| CAPPED_DATA | 2 | len | 1 |
| DATA_SOURCE | 1 | msg | $1 |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_controllen | 0-s32max[c] |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 1-18446744073709551614 |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | msg->msg_namelen | 0-128 |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | 2-s32max[c] |
| USER_PTR | 1 | msg->msg_control | |
| USER_PTR | 1 | msg->msg_name | |
| LOCK2 | sk | ||
| HALF_LOCKED2 | &vq->mutex |
crypto/af_alg.c af_alg_sendmsg() -> memcpy_from_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | data | 18379471554275704832,18446612682070032384 |
| PARAM_VALUE | 1 | msg | 4096-ptr_max |
| PARAM_VALUE | 2 | len | 0-4096 |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16,24,36-s32max |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,28,128 |
| BUF_SIZE | 1 | msg->msg_ubuf | (-1),16 |
| CAPPED_DATA | 2 | len | 1 |
| DATA_SOURCE | 1 | msg | $1 |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_controllen | 0-s32max[c] |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 1-18446744073709551614 |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | msg->msg_namelen | 0-128 |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | 2-4095[c] |
| USER_PTR | 1 | msg->msg_control | |
| USER_PTR | 1 | msg->msg_name | |
| LOCK2 | sk | ||
| HALF_LOCKED2 | &vq->mutex |
drivers/net/ppp/pppoe.c pppoe_sendmsg() -> memcpy_from_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 1 | msg | 4096-ptr_max |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16,24,36-s32max |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,28,128 |
| BUF_SIZE | 1 | msg->msg_ubuf | (-1),16 |
| CAPPED_DATA | 2 | len | 1 |
| DATA_SOURCE | 1 | msg | $1 |
| DATA_SOURCE | 2 | len | $2 |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_controllen | 0-s32max[c] |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 1-18446744073709551614 |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | msg->msg_namelen | 0-128 |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | 1-s32max[c] |
| UNITS | 0 | data | unit_byte |
| UNITS | 2 | len | unit_byte |
| USER_PTR | 1 | msg->msg_control | |
| USER_PTR | 1 | msg->msg_name | |
| LOCK2 | sk | ||
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk |
net/nfc/llcp_commands.c nfc_llcp_send_i_frame() -> memcpy_from_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | data | 16,4096-ptr_max |
| PARAM_VALUE | 1 | msg | 4096-ptr_max |
| PARAM_VALUE | 2 | len | 0-4000000 |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16,24,36-s32max |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,28,128 |
| BUF_SIZE | 1 | msg->msg_ubuf | (-1),16 |
| DATA_SOURCE | 0 | data | r _kmalloc_noprof |
| DATA_SOURCE | 1 | msg | $1 |
| DATA_SOURCE | 2 | len | $2 |
| BIT_INFO | 1 | msg->msg_flags | 0x0,0xfffffffe |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_controllen | 0-s32max[c] |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 1-18446744073709551614 |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | msg->msg_namelen | 0-128 |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | 0-4000000 |
| BYTE_COUNT | 0 | ==data2 | 8050 |
| USER_PTR | 1 | msg->msg_control | |
| USER_PTR | 1 | msg->msg_name | |
| HALF_LOCKED2 | &vq->mutex |
net/nfc/llcp_commands.c nfc_llcp_send_ui_frame() -> memcpy_from_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | data | 16,4096-ptr_max |
| PARAM_VALUE | 1 | msg | 4096-ptr_max |
| PARAM_VALUE | 1 | msg->msg_namelen | s32min-(-1),96-s32max |
| PARAM_VALUE | 2 | len | 0-4000000 |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16,24,36-s32max |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,28,128 |
| BUF_SIZE | 1 | msg->msg_ubuf | (-1),16 |
| DATA_SOURCE | 0 | data | r _kmalloc_noprof |
| DATA_SOURCE | 1 | msg | $3 |
| DATA_SOURCE | 2 | len | $4 |
| BIT_INFO | 1 | msg->msg_flags | 0x0,0xfffffffe |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_controllen | 0-s32max[c] |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 1-18446744073709551614 |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | msg->msg_namelen | 96-128 |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | 0-4000000 |
| BYTE_COUNT | 0 | ==data2 | 8050 |
| USER_PTR | 1 | msg->msg_control | |
| USER_PTR | 1 | msg->msg_name | |
| HALF_LOCKED2 | &vq->mutex |
net/l2tp/l2tp_ppp.c pppol2tp_sendmsg() -> memcpy_from_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | data | 4096-ptr_max |
| PARAM_VALUE | 1 | msg | 4096-ptr_max |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16,24,36-s32max |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,28,128 |
| BUF_SIZE | 1 | msg->msg_ubuf | (-1),16 |
| DATA_SOURCE | 1 | msg | $1 |
| DATA_SOURCE | 2 | len | $2 |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_controllen | 0-s32max[c] |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 1-18446744073709551614 |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | msg->msg_namelen | 0-128 |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | s32min-s32max |
| UNITS | 2 | len | unit_byte |
| USER_PTR | 1 | msg->msg_control | |
| USER_PTR | 1 | msg->msg_name | |
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk |
net/ieee802154/socket.c dgram_sendmsg() -> memcpy_from_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | data | 4096-ptr_max |
| PARAM_VALUE | 1 | msg | 4096-ptr_max |
| PARAM_VALUE | 1 | msg->msg_name | 0,4096-ptr_max |
| PARAM_VALUE | 2 | len | 0-127 |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16,24,36-s32max |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,28,128 |
| BUF_SIZE | 1 | msg->msg_ubuf | (-1),16 |
| CAPPED_DATA | 2 | len | 1 |
| DATA_SOURCE | 1 | msg | $1 |
| DATA_SOURCE | 2 | len | $2 |
| BIT_INFO | 1 | msg->msg_flags | 0x0,0xfffffffe |
| NOSPEC | 1 | msg->msg_iter.count | |
| NOSPEC | 2 | len | |
| NOSPEC | 2 | len | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_controllen | 0-s32max[c] |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 1-18446744073709551614 |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | msg->msg_namelen | 0-128 |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | 1-127[c] |
| UNITS | 2 | len | unit_byte |
| USER_PTR | 1 | msg->msg_control | |
| USER_PTR | 1 | msg->msg_name | |
| HALF_LOCKED2 | &vq->mutex |
net/ieee802154/socket.c raw_sendmsg() -> memcpy_from_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | data | 4096-ptr_max |
| PARAM_VALUE | 1 | msg | 4096-ptr_max |
| PARAM_VALUE | 2 | len | 1-127 |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16,24,36-s32max |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,28,128 |
| BUF_SIZE | 1 | msg->msg_ubuf | (-1),16 |
| DATA_SOURCE | 1 | msg | $1 |
| DATA_SOURCE | 2 | len | $2 |
| BIT_INFO | 1 | msg->msg_flags | 0x0,0xfffffffe |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_controllen | 0-s32max[c] |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 1-18446744073709551614 |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | msg->msg_namelen | 0-128 |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | 1-127 |
| UNITS | 2 | len | unit_byte |
| USER_PTR | 1 | msg->msg_control | |
| USER_PTR | 1 | msg->msg_name | |
| HALF_LOCKED2 | &vq->mutex |
net/mctp/af_mctp.c mctp_sendmsg() -> memcpy_from_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | data | 4096-ptr_max |
| PARAM_VALUE | 1 | msg | 4096-ptr_max |
| PARAM_VALUE | 1 | msg->msg_name | 4096-ptr_max |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16,24,36-s32max |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,28,128 |
| BUF_SIZE | 1 | msg->msg_ubuf | (-1),16 |
| DATA_SOURCE | 1 | msg | $1 |
| DATA_SOURCE | 2 | len | $2 |
| CAPABLE | 0 | 13 | |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_controllen | 0-s32max[c] |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 1-18446744073709551614 |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | msg->msg_namelen | 0-128 |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | s32min-s32max |
| UNITS | 2 | len | unit_byte |
| USER_PTR | 1 | msg->msg_control | |
| USER_PTR | 1 | msg->msg_name | |
| HALF_LOCKED2 | sk |
net/ipv6/raw.c rawv6_probe_proto_opt() -> memcpy_from_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 1 | msg | 4096-ptr_max |
| PARAM_VALUE | 2 | len | 2 |
| BUF_SIZE | 0 | data | 4 |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk |
net/ipv6/raw.c rawv6_probe_proto_opt() -> memcpy_from_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 1 | msg | 4096-ptr_max |
| PARAM_VALUE | 2 | len | 4 |
| BUF_SIZE | 0 | data | 4 |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk |
net/ipv6/raw.c rawv6_send_hdrinc() -> memcpy_from_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | data | 4096-ptr_max |
| PARAM_VALUE | 1 | msg | 4096-ptr_max |
| PARAM_VALUE | 1 | msg->msg_name | 0,4096-ptr_max |
| PARAM_VALUE | 2 | len | 40-s32max |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16,24,36-s32max |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,28,128 |
| BUF_SIZE | 1 | msg->msg_ubuf | (-1),16 |
| CAPPED_DATA | 1 | msg->msg_controllen | 1 |
| CAPPED_DATA | 2 | len | 1 |
| DATA_SOURCE | 0 | data | r ipv6_hdr |
| DATA_SOURCE | 1 | msg | $1 |
| DATA_SOURCE | 2 | len | $2 |
| FUZZY_MAX | 2 | len | 40 |
| BIT_INFO | 1 | msg->msg_flags | 0x0,0xfffffffe |
| NOSPEC | 1 | msg->msg_controllen | |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_controllen | 0-s32max[c] |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 1-18446744073709551614 |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | msg->msg_namelen | 0-128 |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | 40-s32max[c] |
| UNITS | 2 | len | unit_byte |
| USER_PTR | 1 | msg->msg_control | |
| USER_PTR | 1 | msg->msg_name | |
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk |
net/vmw_vsock/vmci_transport.c vmci_transport_dgram_enqueue() -> memcpy_from_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | *data | 0-255 |
| PARAM_VALUE | 1 | msg | 4096-ptr_max |
| PARAM_VALUE | 2 | len | 0-69608 |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16,24,36-s32max |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,28,128 |
| BUF_SIZE | 1 | msg->msg_ubuf | (-1),16 |
| DATA_SOURCE | 1 | msg | $2 |
| DATA_SOURCE | 2 | len | $3 |
| BIT_INFO | 1 | msg->msg_flags | 0x0,0xfffffffe |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_controllen | 0-s32max[c] |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 1-18446744073709551614 |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | msg->msg_namelen | 0-128 |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | 0-69608 |
| UNITS | 0 | data | unit_byte |
| UNITS | 2 | len | unit_byte |
| BYTE_COUNT | 0 | ==data2 | 8050 |
| USER_PTR | 1 | msg->msg_control | |
| USER_PTR | 1 | msg->msg_name | |
| LOCK2 | sk | ||
| HALF_LOCKED2 | &vq->mutex |
crypto/algif_rng.c rng_test_sendmsg() -> memcpy_from_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | data | 16,4096-ptr_max |
| PARAM_VALUE | 0 | *data | 0-255 |
| PARAM_VALUE | 1 | msg | 4096-ptr_max |
| PARAM_VALUE | 2 | len | 0-128 |
| BUF_SIZE | 0 | data | 0-128 |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16,24,36-s32max |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,28,128 |
| BUF_SIZE | 1 | msg->msg_ubuf | (-1),16 |
| DATA_SOURCE | 0 | data | r _kmalloc_noprof |
| DATA_SOURCE | 1 | msg | $1 |
| DATA_SOURCE | 2 | len | $2 |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_controllen | 0-s32max[c] |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 1-18446744073709551614 |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | msg->msg_namelen | 0-128 |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | 0-128 |
| BYTE_COUNT | 0 | ==data2 | 8050 |
| USER_PTR | 1 | msg->msg_control | |
| USER_PTR | 1 | msg->msg_name | |
| LOCK2 | sock->sk | ||
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk |
net/can/j1939/socket.c j1939_sk_alloc_skb() -> memcpy_from_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | data | 4096-ptr_max |
| PARAM_VALUE | 1 | msg | 4096-ptr_max |
| PARAM_VALUE | 1 | msg->msg_name | 0,4096-ptr_max |
| PARAM_VALUE | 2 | len | 0-1785 |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16,24,36-s32max |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,28,128 |
| BUF_SIZE | 1 | msg->msg_ubuf | (-1),16 |
| CAPPED_DATA | 2 | len | 1 |
| DATA_SOURCE | 1 | msg | $2 |
| DATA_SOURCE | 2 | len | $3 |
| NOSPEC | 1 | msg->msg_iter.count | |
| NOSPEC | 2 | len | |
| NOSPEC | 2 | len | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_controllen | 0-s32max[c] |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | msg->msg_namelen | 0-128 |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | 1-1785[c] |
| UNITS | 2 | len | unit_byte |
| USER_PTR | 1 | msg->msg_control | |
| USER_PTR | 1 | msg->msg_name | |
| LOCK2 | sock->sk | ||
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk |
net/x25/af_x25.c x25_sendmsg() -> memcpy_from_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | data | 4096-ptr_max |
| PARAM_VALUE | 0 | *data | 0-255 |
| PARAM_VALUE | 1 | msg | 4096-ptr_max |
| PARAM_VALUE | 1 | msg->msg_flags | 1-u32max |
| PARAM_VALUE | 2 | len | 0-u16max |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16,24,36-s32max |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,28,128 |
| BUF_SIZE | 1 | msg->msg_ubuf | (-1),16 |
| DATA_SOURCE | 1 | msg | $1 |
| DATA_SOURCE | 2 | len | $2 [m] |
| BIT_INFO | 1 | msg->msg_flags | 0x0,0x800000c1 |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_controllen | 0-s32max[c] |
| USER_DATA | 1 | msg->msg_flags | 1-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 1-18446744073709551614 |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | msg->msg_namelen | 0-128 |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | 0-u16max |
| USER_PTR | 1 | msg->msg_control | |
| USER_PTR | 1 | msg->msg_name | |
| LOCK2 | sk | ||
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk |
net/netlink/af_netlink.c netlink_sendmsg() -> memcpy_from_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | data | 4096-ptr_max |
| PARAM_VALUE | 1 | msg | 4096-ptr_max |
| PARAM_VALUE | 1 | msg->msg_namelen | s32min-0,12-s32max |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16,24,36-s32max |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,28,128 |
| BUF_SIZE | 1 | msg->msg_ubuf | (-1),16 |
| CAPPED_DATA | 2 | len | 1 |
| DATA_SOURCE | 1 | msg | $1 |
| DATA_SOURCE | 2 | len | $2 |
| BIT_INFO | 1 | msg->msg_flags | 0x0,0xfffffffe |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_controllen | 0-s32max[c] |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 1-18446744073709551614 |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | msg->msg_namelen | 0,12-128 |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | 2-s32max[c] |
| UNITS | 2 | len | unit_byte |
| USER_PTR | 1 | msg->msg_control | |
| USER_PTR | 1 | msg->msg_name | |
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk |