Linux driver-core infrastructure
 help / color / mirror / Atom feed
* [PATCH] kobject: fix out-of-bounds read in action parser
@ 2026-08-18  6:26 Jiacheng Xu
  2026-08-24 17:32 ` Vishal Moola (Fractile)
  0 siblings, 1 reply; 10+ messages in thread
From: Jiacheng Xu @ 2026-08-18  6:26 UTC (permalink / raw)
  To: gregkh, rafael, dakr; +Cc: akpm, driver-core

kobject_action_type() uses the position of the first space in the input
as the length of the uevent action.  It then checks the byte at that
position in the corresponding action string.

An embedded NUL byte can make strncmp() report a match while
count_first is already greater than the actual length of the action
string.  For example, the input "bind\0 ..." makes the parser access
kobject_actions[KOBJ_BIND][5], which is beyond the end of the "bind"
string.

Use strlen() to verify that the input action length exactly matches the
known action string before accepting the match.  This avoids indexing
the action string with an out-of-bounds offset.

Fixes: f36776fafbaa ("kobject: support passing in variables for synthetic uevents")
Signed-off-by: Jiacheng Xu <stitch@zju.edu.cn>
---
lib/kobject_uevent.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/lib/kobject_uevent.c b/lib/kobject_uevent.c
index ddbc4d7482d2..b03562301bfe 100644
--- a/lib/kobject_uevent.c
+++ b/lib/kobject_uevent.c
@@ -83,7 +83,7 @@ static int kobject_action_type(const char *buf, size_t count,
for (action = 0; action < ARRAY_SIZE(kobject_actions); action++) {
        if (strncmp(kobject_actions[action], buf, count_first) != 0)
                continue;
-             if (kobject_actions[action][count_first] != '\0')
+             if (strlen(kobject_actions[action]) != count_first)
                continue;
        if (args)
                *args = args_start;

^ permalink raw reply related	[flat|nested] 10+ messages in thread

end of thread, other threads:[~2026-08-25 12:12 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-18  6:26 [PATCH] kobject: fix out-of-bounds read in action parser Jiacheng Xu
2026-08-24 17:32 ` Vishal Moola (Fractile)
2026-08-25  3:54   ` Jiacheng Xu
2026-08-25  3:57   ` [PATCH v2] " Jiacheng Xu
2026-08-25  5:33     ` Greg KH
2026-08-25  6:26       ` [PATCH] " Jiacheng Xu
2026-08-25  6:46         ` Greg KH
2026-08-25  7:05       ` [PATCH v2 RESEND] kobject: fix out-of-bounds access in kobject_action_type() Jiacheng Xu
2026-08-25  7:35         ` Greg KH
2026-08-25 12:12         ` Vishal Moola (Fractile)

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox