[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[PATCH v2 2/3] xenbus/store: guard against NULL payload in StoreParseWatchEvent


  • To: win-pv-devel@xxxxxxxxxxxxxxxxxxxx
  • From: david ambu <david.preetham@xxxxxxxxxx>
  • Date: Mon, 14 Sep 2026 11:16:02 +0100
  • Authentication-results: eu.smtp.expurgate.cloud; dkim=pass header.s=google header.d=citrix.com header.i="@citrix.com" header.h="Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID:Date:Subject:Cc:To:From"
  • Cc: david ambu <david.preetham@xxxxxxxxxx>
  • Delivery-date: Mon, 14 Sep 2026 10:17:48 +0000
  • List-id: Developer list for the Windows PV Drivers subproject <win-pv-devel.lists.xenproject.org>

Add NULL and zero-length check at the start of StoreParseWatchEvent
to avoid dereferencing a NULL Data pointer.

Assisted-by: ClaudeCode:claude-sonnet-4-6
Signed-off-by: david ambu <david.preetham@xxxxxxxxxx>
---
 src/xenbus/store.c | 18 ++++++++++++------
 1 file changed, 12 insertions(+), 6 deletions(-)

diff --git a/src/xenbus/store.c b/src/xenbus/store.c
index d1b396b..bd9067e 100644
--- a/src/xenbus/store.c
+++ b/src/xenbus/store.c
@@ -623,21 +623,24 @@ StoreParseWatchEvent(
 {
     PSTR            End;
 
+    if (Data == NULL || Length == 0)
+        goto fail1;
+
     *Path = Data;
-    while (*Data != '\0' && Length != 0) {
+    while (Length != 0 && *Data != '\0') {
         Data++;
         --Length;
     }
 
     if (Length != TOKEN_LENGTH + 1)
-        goto fail1;
+        goto fail2;
 
     // Skip over the NUL
     Data++;
     --Length;
 
     if (Data[Length - 1] != '\0')
-        goto fail2;
+        goto fail3;
 
     if (strncmp(Data, "TOK|", 4) != 0) {
         Warning("UNRECOGNIZED PRE-AMBLE: %02X%02X%02X%02X\n",
@@ -646,23 +649,26 @@ StoreParseWatchEvent(
                 Data[2],
                 Data[3]);
 
-        goto fail3;
+        goto fail4;
     }
 
     Data += 4;
     *Caller = (PVOID)(ULONG_PTR)_strtoui64(Data, &End, 16);
 
     if (*End != '|')
-        goto fail4;
+        goto fail5;
 
     Data = End + 1;
     *Id = (USHORT)strtoul(Data, &End, 16);
 
     if (*End != '\0')
-        goto fail5;
+        goto fail6;
 
     return STATUS_SUCCESS;
 
+fail6:
+    Error("fail6\n");
+
 fail5:
     Error("fail5\n");
 
-- 
2.51.0.windows.1




 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.