From 5badf4d37607e3525b4d04ac6b2d95ebb1a4d4cd Mon Sep 17 00:00:00 2001 From: Joachim Wiberg Date: Sun, 7 Mar 2021 12:31:17 +0100 Subject: [PATCH] plugins: pidfile: validate against read() length, not buffer size Fix ev->len validation; must check against sz read(), not total buffer size. Also, fix off-by-one in comparison. Signed-off-by: Joachim Wiberg --- plugins/pidfile.c | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/plugins/pidfile.c b/plugins/pidfile.c index 3bd1a7a9..89bf5985 100644 --- a/plugins/pidfile.c +++ b/plugins/pidfile.c @@ -151,7 +151,8 @@ static void pidfile_callback(void *arg, int fd, int events) { static char ev_buf[8 *(sizeof(struct inotify_event) + NAME_MAX + 1) + 1]; struct inotify_event *ev; - ssize_t sz, off; + ssize_t sz; + size_t off; sz = read(fd, ev_buf, sizeof(ev_buf) - 1); if (sz <= 0) { @@ -160,14 +161,14 @@ static void pidfile_callback(void *arg, int fd, int events) } ev_buf[sz] = 0; - for (off = 0; off < sz; off += sizeof(*ev) + ev->len) { + for (off = 0; off < (size_t)sz; off += sizeof(*ev) + ev->len) { struct iwatch_path *iwp; - if (off + sizeof(*ev) >= sizeof(ev_buf)) + if (off + sizeof(*ev) > (size_t)sz) break; ev = (struct inotify_event *)&ev_buf[off]; - if (off + sizeof(*ev) + ev->len >= sizeof(ev_buf)) + if (off + sizeof(*ev) + ev->len > (size_t)sz) break; if (!ev->mask)