From: Junio C Hamano Date: Tue, 08 Sep 2026 01:17:01 GMT Subject: Re: [PATCH 2/3] imap-send: don't expect an ASN1_STRING to be NUL-terminated Message-ID: In-Reply-To: <20260907211210.2621693-3-dev+git@drbeat.li> Beat Bolli writes: > - const char *pattern = (const char *)ASN1_STRING_get0_data(asn1_str); > + int ret = 0; > + size_t len = ASN1_STRING_get_length(asn1_str); > + char *pattern = xmemdupz(ASN1_STRING_get0_data(asn1_str), len); > > /* embedded NUL characters may open a security hole */ > - if (memchr(pattern, '\0', ASN1_STRING_get_length(asn1_str))) > - return 0; > + if (memchr(pattern, '\0', len)) > + goto out; > > if (pattern[0] == '*' && pattern[1] == '.') { > pattern += 2; > if (!(host = strchr(host, '.'))) > - return 0; > + goto out; > host++; > } > > - return *host && *pattern && !strcasecmp(host, pattern); > + ret = *host && *pattern && !strcasecmp(host, pattern); > +out: > + free(pattern); There is a code path that increments the "pattern" variable by 2. Running free() on it would not have a pleasant outcome. The pattern we often employ in our codebase is to have a separate variable "char *pattern_to_free" and have it used only for a call to free(). > + return ret; > } > > static int verify_hostname(X509 *cert, const char *hostname)