git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[patch] git: fix overflow in update-cache.c

From
IMIngo Molnar <mingo@elte.hu>
Date
Apr 14, 2005, 12:18 UTC
Message-ID
<20050414121819.GA14380@elte.hu>
In-Reply-To
<20050414120834.GA14290@elte.hu>

this patch fixes a 1-byte overflow in update-cache.c (probably not exploitable). A specially crafted db object might trigger this overflow.

the bug is that normally the 'type' field is parsed by read_sha1_file(), via:

        if (sscanf(buffer, "%10s %lu", type, size) != 2)

i.e. 0-10 long strings, which take 1-11 bytes of space. Normally the type strings are stored in char [20] arrays, but in update-cache.c that is char [10], so a 1 byte overflow might occur.

This should not happen with a 'friendly' DB, as the longest type string ("commit") is 7 bytes long. The fix is to use the customary char [20].

(someone might want to clean those open-coded constants up with a TYPE_LEN define, they do tend to cause problems like this. I'm not against open-coded constants (they make code much more readable), but for fields that get filled in from possibly hostile objects this is playing with fire.)

hey, this might be the first true security fix for GIT? ;-)
	Ingo
Signed-off-by: Ingo Molnar <mingo@elte.hu>

--- update-cache.c.orig +++ update-cache.c

@@ -139,7 +139,7 @@ static int compare_data(struct cache_ent
 	if (fd >= 0) {
 		void *buffer;
 		unsigned long size;
-		char type[10];
+		char type[20];
 
 		buffer = read_sha1_file(ce->sha1, type, &size);
 		if (buffer) {
Previous: Ingo MolnarNext: Ingo Molnar
Message 8 of 22 in “git: fix memory leak in checkout-cache.c”
  1. git: fix memory leak in checkout-cache.cIngo Molnar, Apr 14, 2005
  2. git: fix memory leak #2 in checkout-cache.cIngo Molnar, Apr 14, 2005
  3. git: cleanup in ls-tree.cIngo Molnar, Apr 14, 2005
  4. git: fix memory leaks in read-tree.cIngo Molnar, Apr 14, 2005
  5. git: fix rare memory leak in rev-tree.cIngo Molnar, Apr 14, 2005
  6. git: report parse_commit() errors in rev-tree.cIngo Molnar, Apr 14, 2005
  7. git: fix memory leak in show-diff.cIngo Molnar, Apr 14, 2005
  8. git: fix overflow in update-cache.cIngo Molnar, Apr 14, 2005
  9. cleanup: read_sha1_file() -> malloc_read_sha1_file()Ingo Molnar, Apr 14, 2005
  10. git: fix 1-byte overflow in show-files.cIngo Molnar, Apr 14, 2005
  11. Petr BaudisApr 17, 2005
  12. Ingo MolnarApr 18, 2005
  13. git: fix memory leaks in update-cache.cIngo Molnar, Apr 14, 2005
  14. git: clean up add_file_to_cache() in update-cache.cIngo Molnar, Apr 14, 2005
  15. git: fix memory leak #3 in update-cache.cIngo Molnar, Apr 14, 2005
  16. git: fix memory leaks in read-cache.cIngo Molnar, Apr 14, 2005
  17. git: fix memory leak #2 in read-cache.cIngo Molnar, Apr 14, 2005
  18. Ingo MolnarApr 14, 2005
  19. Martin SchlemmerApr 14, 2005
  20. Linus TorvaldsApr 14, 2005
  21. Ingo MolnarApr 14, 2005
  22. git: fix memory leak in write-tree.cIngo Molnar, Apr 14, 2005

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.