mirror of
https://github.com/troglobit/finit.git
synced 2026-09-30 21:13:01 +07:00
plugins: netlink: stricter interface name validation
Coverity suggests validating against only a set of known characters. However, the kernel allows just about all characters in an interface name. This version of valdiate_ifname() is blatantly stolen, more or less, from linux/net/core/dev.c https://code.woboq.org/linux/linux/net/core/dev.c.html#1020 Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This commit is contained in:
+3
-3
@@ -117,14 +117,14 @@ static int validate_ifname(const char *ifname)
|
|||||||
if (!ifname || !ifname[0])
|
if (!ifname || !ifname[0])
|
||||||
return 1;
|
return 1;
|
||||||
|
|
||||||
if (strlen(ifname) >= IFNAMSIZ)
|
if (strnlen(ifname, IFNAMSIZ) == IFNAMSIZ)
|
||||||
return 1;
|
return 1;
|
||||||
|
|
||||||
if (strstr(ifname, ".."))
|
if (!strcmp(ifname, ".") || !strcmp(ifname, ".."))
|
||||||
return 1;
|
return 1;
|
||||||
|
|
||||||
while (*ifname) {
|
while (*ifname) {
|
||||||
if (*ifname == '/' || isspace(*ifname))
|
if (*ifname == '/' || *ifname == ':' || isspace(*ifname))
|
||||||
return 1;
|
return 1;
|
||||||
ifname++;
|
ifname++;
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user