git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] fsmonitor: avoid global-buffer-overflow READ when checking trivial response

From
Junio C Hamano <gitster@pobox.com>
Date
Mar 17, 2021, 17:10 UTC
Message-ID
<xmqq7dm5zox7.fsf@gitster.g>
In-Reply-To
<c34badb9-a3bc-a5fe-c6fc-c1bdce867e0d@jeffhostetler.com>
Jeff Hostetler <git@jeffhostetler.com> writes:
Show 14 quoted lines
> On 3/15/21 12:39 PM, Andrzej Hunt via GitGitGadget wrote:
>> From: Andrzej Hunt <ajrhunt@google.com>
>> query_result can be be an empty strbuf (STRBUF_INIT) - in that case
>> trying to read 3 bytes triggers a buffer overflow read (as
>> query_result.buf = '\0').
>> Therefore we need to check query_result's length before trying to
>> read 3
>> bytes.
>> This overflow was introduced in:
>>    940b94f35c (fsmonitor: log invocation of FSMonitor hook to trace2, 2021-02-03)
>> It was found when running the test-suite against ASAN, and can be most
>> easily reproduced with the following command:
> ...
> Looks good to me.  And thanks for catching this.
Thanks, will queue on jh/fsmonitor-prework as a maint-2.31 candidate.
Previous: Jeff Hostetler
Message 4 of 4 in “fsmonitor: avoid global-buffer-overflow READ when checking trivial response”
  1. fsmonitor: avoid global-buffer-overflow READ when checking trivial responseAndrzej Hunt via GitGitGadget, Mar 15, 2021
  2. Bagas SanjayaMar 16, 2021
  3. Jeff HostetlerMar 16, 2021
  4. Junio C HamanoMar 17, 2021

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.