git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 2/3] imap-send: don't expect an ASN1_STRING to be NUL-terminated

From
Junio C Hamano <gitster@pobox.com>
Date
Sep 8, 2026, 01:17 UTC
Message-ID
<xmqqwlswzgmq.fsf@gitster.g>
In-Reply-To
<20260907211210.2621693-3-dev+git@drbeat.li>
Beat Bolli <dev+git@drbeat.li> writes:
Show 23 quoted lines
> -	const char *pattern = (const char *)ASN1_STRING_get0_data(asn1_str);
> +	int ret = 0;
> +	size_t len = ASN1_STRING_get_length(asn1_str);
> +	char *pattern = xmemdupz(ASN1_STRING_get0_data(asn1_str), len);
>  
>  	/* embedded NUL characters may open a security hole */
> -	if (memchr(pattern, '\0', ASN1_STRING_get_length(asn1_str)))
> -	    return 0;
> +	if (memchr(pattern, '\0', len))
> +	    goto out;
>  
>  	if (pattern[0] == '*' && pattern[1] == '.') {
>  		pattern += 2;
>  		if (!(host = strchr(host, '.')))
> -			return 0;
> +			goto out;
>  		host++;
>  	}
>  
> -	return *host && *pattern && !strcasecmp(host, pattern);
> +	ret = *host && *pattern && !strcasecmp(host, pattern);
> +out:
> +	free(pattern);

There is a code path that increments the "pattern" variable by 2. Running free() on it would not have a pleasant outcome.

The pattern we often employ in our codebase is to have a separate variable "char *pattern_to_free" and have it used only for a call to free().

> +	return ret;
>  }
>  
>  static int verify_hostname(X509 *cert, const char *hostname)
Previous: Beat BolliNext: Patrick Steinhardt
Message 5 of 11 in “imap-send: future proofing and two correctness fixes”
  1. 0/3 imap-send: future proofing and two correctness fixesBeat Bolli, Sep 7, 2026
  2. 3/3 imap-send: only check the CN if no SAN DNS names are presentBeat Bolli, Sep 7, 2026
  3. brian m. carlsonSep 8, 2026
  4. 2/3 imap-send: don't expect an ASN1_STRING to be NUL-terminatedBeat Bolli, Sep 7, 2026
  5. Junio C HamanoSep 8, 2026
  6. Patrick SteinhardtSep 8, 2026
  7. 1/3 imap-send: prepare for OpenSSL 4.1Beat Bolli, Sep 7, 2026
  8. Junio C HamanoSep 8, 2026
  9. Patrick SteinhardtSep 8, 2026
  10. Beat BolliSep 14, 2026
  11. Patrick SteinhardtSep 23, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.