[PATCH] Prevent a short allocation by checking upper_length

Colin Wee <[email protected]>
Newsgroups dev.linux.lists.connman
Message-ID <lvq5tor4tudvh4xtxy47p3cescldr3v5c3fijgrqwkdfrktq5g@ycqxblnjgbaj>
Hey Connman Maintainers,

I'd like to submit a patch fixing potential memory corruption in
connman. I've attached it for review, please let me know what you think.

-Colin
0001-Prevent-a-short-allocation-by-checking-upper_length.patch (text/x-patch, 759 B)
From c9452e34e45be8b54fac0996464f4a5487799377 Mon Sep 17 00:00:00 2001
From: Tesla OpenSource <[email protected]>
Date: Fri, 3 May 2024 14:50:22 -0700
Subject: [PATCH] Prevent a short allocation by checking upper_length

---
 gdhcp/client.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/gdhcp/client.c b/gdhcp/client.c
index 2afa19e6..c9234a18 100644
--- a/gdhcp/client.c
+++ b/gdhcp/client.c
@@ -1863,6 +1863,8 @@ static char *malloc_option_value_string(uint8_t *option, GDHCPOptionType type)
 		return NULL;
 	upper_length = len_of_option_as_string[type] *
 			((unsigned)len / (unsigned)optlen);
+	if (upper_length == 0)
+		return NULL;
 	dest = ret = g_malloc(upper_length + 1);
 	if (!ret)
 		return NULL;
-- 
2.45.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.