chiark / gitweb /
sd-bus: check for potential integer overflow in KDBUS_ITEM_FOREACH()
authorDaniel Mack <zonque@gmail.com>
Sat, 8 Mar 2014 13:18:48 +0000 (14:18 +0100)
committerDaniel Mack <zonque@gmail.com>
Sat, 8 Mar 2014 13:18:48 +0000 (14:18 +0100)
For large values of item->size, the 'part' pointer can wrap around,
which results in an illegal pointer, but currently passes the for-loop
condition.

src/libsystemd/sd-bus/bus-kernel.h

index c4722cbac60988b60c71af9a9ba4d1d04341d620..a1e9691f1d3cab4da88f67ac384c4ca14e661b36 100644 (file)
@@ -31,7 +31,8 @@
 
 #define KDBUS_ITEM_FOREACH(part, head, first)                           \
         for (part = (head)->first;                                      \
-             (uint8_t *)(part) < (uint8_t *)(head) + (head)->size;      \
+             ((uint8_t *)(part) < (uint8_t *)(head) + (head)->size) &&  \
+                ((uint8_t *) part >= (uint8_t *) head);                 \
              part = KDBUS_ITEM_NEXT(part))
 
 #define KDBUS_ITEM_HEADER_SIZE offsetof(struct kdbus_item, data)