|
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] Re: [PATCH v2 1/2] xenbus/store: guard against NULL payload in StoreParseWatchEvent
On 14/09/2026 15:14, david ambu wrote:
> Add NULL and zero-length check at the start of StoreParseWatchEvent
> to avoid dereferencing a NULL Data pointer.
>
> Signed-off-by: david ambu <david.preetham@xxxxxxxxxx>
> Assisted-by: ClaudeCode:claude-sonnet-4-6
Both patches:
Reviewed-by: Tu Dinh <ngoc-tu.dinh@xxxxxxxxxx>
> ---
> src/xenbus/store.c | 18 ++++++++++++------
> 1 file changed, 12 insertions(+), 6 deletions(-)
>
> diff --git a/src/xenbus/store.c b/src/xenbus/store.c
> index d1b396b..bd9067e 100644
> --- a/src/xenbus/store.c
> +++ b/src/xenbus/store.c
> @@ -623,21 +623,24 @@ StoreParseWatchEvent(
> {
> PSTR End;
>
> + if (Data == NULL || Length == 0)
> + goto fail1;
> +
> *Path = Data;
> - while (*Data != '\0' && Length != 0) {
> + while (Length != 0 && *Data != '\0') {
> Data++;
> --Length;
> }
>
> if (Length != TOKEN_LENGTH + 1)
> - goto fail1;
> + goto fail2;
>
> // Skip over the NUL
> Data++;
> --Length;
>
> if (Data[Length - 1] != '\0')
> - goto fail2;
> + goto fail3;
>
> if (strncmp(Data, "TOK|", 4) != 0) {
> Warning("UNRECOGNIZED PRE-AMBLE: %02X%02X%02X%02X\n",
> @@ -646,23 +649,26 @@ StoreParseWatchEvent(
> Data[2],
> Data[3]);
>
> - goto fail3;
> + goto fail4;
> }
>
> Data += 4;
> *Caller = (PVOID)(ULONG_PTR)_strtoui64(Data, &End, 16);
>
> if (*End != '|')
> - goto fail4;
> + goto fail5;
>
> Data = End + 1;
> *Id = (USHORT)strtoul(Data, &End, 16);
>
> if (*End != '\0')
> - goto fail5;
> + goto fail6;
>
> return STATUS_SUCCESS;
>
> +fail6:
> + Error("fail6\n");
> +
> fail5:
> Error("fail5\n");
>
--
Ngoc Tu Dinh | Vates XCP-ng Developer
XCP-ng & Xen Orchestra - Vates solutions
web: https://vates.tech
|
![]() |
Lists.xenproject.org is hosted with RackSpace, monitoring our |