From: Phil Sutter <phil@nwl.cc>
To: Pablo Neira Ayuso <pablo@netfilter.org>
Cc: netfilter-devel@vger.kernel.org
Subject: [conntrack-tools PATCH 3/8] Fix potential buffer overrun in snprintf() calls
Date: Fri, 25 Mar 2022 11:49:58 +0100 [thread overview]
Message-ID: <20220325105003.26621-4-phil@nwl.cc> (raw)
In-Reply-To: <20220325105003.26621-1-phil@nwl.cc>
When consecutively printing into the same buffer at increasing offset,
reduce buffer size passed to snprintf() to not defeat its size checking.
Signed-off-by: Phil Sutter <phil@nwl.cc>
---
src/process.c | 2 +-
src/queue.c | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/src/process.c b/src/process.c
index 3ddad5ffa7959..08598eeae84de 100644
--- a/src/process.c
+++ b/src/process.c
@@ -84,7 +84,7 @@ void fork_process_dump(int fd)
int size = 0;
list_for_each_entry(this, &process_list, head) {
- size += snprintf(buf+size, sizeof(buf),
+ size += snprintf(buf + size, sizeof(buf) - size,
"PID=%u type=%s\n",
this->pid,
this->type < CTD_PROC_MAX ?
diff --git a/src/queue.c b/src/queue.c
index 76425b18495b5..e94dc7c45d1fd 100644
--- a/src/queue.c
+++ b/src/queue.c
@@ -69,12 +69,12 @@ void queue_stats_show(int fd)
int size = 0;
char buf[512];
- size += snprintf(buf+size, sizeof(buf),
+ size += snprintf(buf + size, sizeof(buf) - size,
"allocated queue nodes:\t\t%12u\n\n",
qobjects_num);
list_for_each_entry(this, &queue_list, list) {
- size += snprintf(buf+size, sizeof(buf),
+ size += snprintf(buf + size, sizeof(buf) - size,
"queue %s:\n"
"current elements:\t\t%12u\n"
"maximum elements:\t\t%12u\n"
--
2.34.1
next prev parent reply other threads:[~2022-03-25 10:50 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2022-03-25 10:49 [conntrack-tools PATCH 0/8] Fixes for a recent Coverity tool run Phil Sutter
2022-03-25 10:49 ` [conntrack-tools PATCH 1/8] hash: Flush tables when destroying Phil Sutter
2022-03-25 10:49 ` [conntrack-tools PATCH 2/8] cache: Fix features array allocation Phil Sutter
2022-03-25 10:49 ` Phil Sutter [this message]
2022-03-25 10:49 ` [conntrack-tools PATCH 4/8] helpers: ftp: Avoid ugly casts Phil Sutter
2022-03-25 10:50 ` [conntrack-tools PATCH 5/8] read_config_yy: Drop extra argument from dlog() call Phil Sutter
2022-03-25 10:50 ` [conntrack-tools PATCH 6/8] Don't call exit() from signal handler Phil Sutter
2022-03-25 10:50 ` [conntrack-tools PATCH 7/8] Drop pointless assignments Phil Sutter
2022-03-25 10:50 ` [conntrack-tools PATCH 8/8] connntrack: Fix for memleak when parsing -j arg Phil Sutter
2022-03-28 8:25 ` [conntrack-tools PATCH 0/8] Fixes for a recent Coverity tool run Pablo Neira Ayuso
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20220325105003.26621-4-phil@nwl.cc \
--to=phil@nwl.cc \
--cc=netfilter-devel@vger.kernel.org \
--cc=pablo@netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.