From 3872077ff169e29f82890f300baaa56c52157f32 Mon Sep 17 00:00:00 2001 From: Joachim Wiberg Date: Thu, 29 Apr 2021 17:19:19 +0200 Subject: [PATCH] plugins: netlink: stricter interface name validation Coverity suggests validating against only a set of known characters. However, the kernel allows just about all characters in an interface name. This version of valdiate_ifname() is blatantly stolen, more or less, from linux/net/core/dev.c https://code.woboq.org/linux/linux/net/core/dev.c.html#1020 Signed-off-by: Joachim Wiberg --- plugins/netlink.c | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/plugins/netlink.c b/plugins/netlink.c index 370e0a30..e09f8d70 100644 --- a/plugins/netlink.c +++ b/plugins/netlink.c @@ -117,14 +117,14 @@ static int validate_ifname(const char *ifname) if (!ifname || !ifname[0]) return 1; - if (strlen(ifname) >= IFNAMSIZ) + if (strnlen(ifname, IFNAMSIZ) == IFNAMSIZ) return 1; - if (strstr(ifname, "..")) + if (!strcmp(ifname, ".") || !strcmp(ifname, "..")) return 1; while (*ifname) { - if (*ifname == '/' || isspace(*ifname)) + if (*ifname == '/' || *ifname == ':' || isspace(*ifname)) return 1; ifname++; }