git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH 2/3] imap-send: don't expect an ASN1_STRING to be NUL-terminated

From
Beat Bolli <dev+git@drbeat.li>
Date
Sep 7, 2026, 21:12 UTC
Message-ID
<20260907211210.2621693-3-dev+git@drbeat.li>
In-Reply-To
<20260907211210.2621693-1-dev+git@drbeat.li>

As highlighted by a recent OpenSSL commit[1], ASN1_STRINGs were never documented to be terminated by a NUL byte, but our code treats the pattern as such in the strcasecmp() call.

Make a NUL-terminated copy to avoid Undefined Behavior.
[1]: https://github.com/openssl/openssl/commit/4b581a4666c3e470a01a7323801b2ba8ccfa478c
     (Add a migration entry for ASN1_STRINGs, 2026-08-06)
Signed-off-by: Beat Bolli <dev+git@drbeat.li>
---
 imap-send.c | 15 ++++++++++-----
 1 file changed, 10 insertions(+), 5 deletions(-)
diff --git a/imap-send.c b/imap-send.c
index 977d78005c..9a807cdde8 100644
--- a/imap-send.c
+++ b/imap-send.c
@@ -226,20 +226,25 @@ static int ssl_socket_connect(struct imap_socket *sock UNUSED,
 
 static int host_matches(const char *host, const ASN1_STRING *asn1_str)
 {
-	const char *pattern = (const char *)ASN1_STRING_get0_data(asn1_str);
+	int ret = 0;
+	size_t len = ASN1_STRING_get_length(asn1_str);
+	char *pattern = xmemdupz(ASN1_STRING_get0_data(asn1_str), len);
 
 	/* embedded NUL characters may open a security hole */
-	if (memchr(pattern, '\0', ASN1_STRING_get_length(asn1_str)))
-	    return 0;
+	if (memchr(pattern, '\0', len))
+	    goto out;
 
 	if (pattern[0] == '*' && pattern[1] == '.') {
 		pattern += 2;
 		if (!(host = strchr(host, '.')))
-			return 0;
+			goto out;
 		host++;
 	}
 
-	return *host && *pattern && !strcasecmp(host, pattern);
+	ret = *host && *pattern && !strcasecmp(host, pattern);
+out:
+	free(pattern);
+	return ret;
 }
 
 static int verify_hostname(X509 *cert, const char *hostname)
-- 
2.53.0
Previous: brian m. carlsonNext: Junio C Hamano
Message 4 of 11 in “imap-send: future proofing and two correctness fixes”
  1. 0/3 imap-send: future proofing and two correctness fixesBeat Bolli, Sep 7, 2026
  2. 3/3 imap-send: only check the CN if no SAN DNS names are presentBeat Bolli, Sep 7, 2026
  3. brian m. carlsonSep 8, 2026
  4. 2/3 imap-send: don't expect an ASN1_STRING to be NUL-terminatedBeat Bolli, Sep 7, 2026
  5. Junio C HamanoSep 8, 2026
  6. Patrick SteinhardtSep 8, 2026
  7. 1/3 imap-send: prepare for OpenSSL 4.1Beat Bolli, Sep 7, 2026
  8. Junio C HamanoSep 8, 2026
  9. Patrick SteinhardtSep 8, 2026
  10. Beat BolliSep 14, 2026
  11. Patrick SteinhardtSep 23, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.