mirror of
https://github.com/troglobit/finit.git
synced 2026-09-30 13:02:37 +07:00
plugins: netlink: stricter interface name validation
Coverity suggests validating against only a set of known characters. However, the kernel allows just about all characters in an interface name. This version of valdiate_ifname() is blatantly stolen, more or less, from linux/net/core/dev.c https://code.woboq.org/linux/linux/net/core/dev.c.html#1020 Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This commit is contained in:
+3
-3
@@ -117,14 +117,14 @@ static int validate_ifname(const char *ifname)
|
||||
if (!ifname || !ifname[0])
|
||||
return 1;
|
||||
|
||||
if (strlen(ifname) >= IFNAMSIZ)
|
||||
if (strnlen(ifname, IFNAMSIZ) == IFNAMSIZ)
|
||||
return 1;
|
||||
|
||||
if (strstr(ifname, ".."))
|
||||
if (!strcmp(ifname, ".") || !strcmp(ifname, ".."))
|
||||
return 1;
|
||||
|
||||
while (*ifname) {
|
||||
if (*ifname == '/' || isspace(*ifname))
|
||||
if (*ifname == '/' || *ifname == ':' || isspace(*ifname))
|
||||
return 1;
|
||||
ifname++;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user