|
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [PATCH 2/3] xenbus/store: guard against NULL payload in StoreParseWatchEvent
Add NULL and zero-length check at the start of StoreParseWatchEvent
to avoid dereferencing a NULL Data pointer.
Assisted-by: ClaudeCode:claude-sonnet-4-6
Signed-off-by: david ambu <david.preetham@xxxxxxxxxx>
---
src/xenbus/store.c | 16 +++++++++++-----
1 file changed, 11 insertions(+), 5 deletions(-)
diff --git a/src/xenbus/store.c b/src/xenbus/store.c
index d1b396b..3bdca38 100644
--- a/src/xenbus/store.c
+++ b/src/xenbus/store.c
@@ -623,6 +623,9 @@ StoreParseWatchEvent(
{
PSTR End;
+ if (Data == NULL || Length == 0)
+ goto fail1;
+
*Path = Data;
while (*Data != '\0' && Length != 0) {
Data++;
@@ -630,14 +633,14 @@ StoreParseWatchEvent(
}
if (Length != TOKEN_LENGTH + 1)
- goto fail1;
+ goto fail2;
// Skip over the NUL
Data++;
--Length;
if (Data[Length - 1] != '\0')
- goto fail2;
+ goto fail3;
if (strncmp(Data, "TOK|", 4) != 0) {
Warning("UNRECOGNIZED PRE-AMBLE: %02X%02X%02X%02X\n",
@@ -646,23 +649,26 @@ StoreParseWatchEvent(
Data[2],
Data[3]);
- goto fail3;
+ goto fail4;
}
Data += 4;
*Caller = (PVOID)(ULONG_PTR)_strtoui64(Data, &End, 16);
if (*End != '|')
- goto fail4;
+ goto fail5;
Data = End + 1;
*Id = (USHORT)strtoul(Data, &End, 16);
if (*End != '\0')
- goto fail5;
+ goto fail6;
return STATUS_SUCCESS;
+fail6:
+ Error("fail6\n");
+
fail5:
Error("fail5\n");
--
2.51.0.windows.1
|
![]() |
Lists.xenproject.org is hosted with RackSpace, monitoring our |