From: Guy Streeter The value of shmmax may be larger than will fit in the struct used by the 32bit compat version of sys_shmctl. This change mirrors what the normal sys_shmctl does when called with the old IPC_INFO command. Signed-off-by: Guy Streeter Signed-off-by: Andrew Morton --- ipc/compat.c | 4 ++++ 1 file changed, 4 insertions(+) diff -puN ipc/compat.c~cap-shmmax-at-int_max-in-compat-shminfo ipc/compat.c --- a/ipc/compat.c~cap-shmmax-at-int_max-in-compat-shminfo +++ a/ipc/compat.c @@ -542,6 +542,8 @@ static inline int put_compat_shminfo64(s if (!access_ok(VERIFY_WRITE, up64, sizeof(*up64))) return -EFAULT; + if (smi->shmmax > INT_MAX) + smi->shmmax = INT_MAX; err = __put_user(smi->shmmax, &up64->shmmax); err |= __put_user(smi->shmmin, &up64->shmmin); err |= __put_user(smi->shmmni, &up64->shmmni); @@ -557,6 +559,8 @@ static inline int put_compat_shminfo(str if (!access_ok(VERIFY_WRITE, up, sizeof(*up))) return -EFAULT; + if (smi->shmmax > INT_MAX) + smi->shmmax = INT_MAX; err = __put_user(smi->shmmax, &up->shmmax); err |= __put_user(smi->shmmin, &up->shmmin); err |= __put_user(smi->shmmni, &up->shmmni); _