public inbox for iwd@lists.linux.dev
 help / color / mirror / Atom feed
From: James Prestwood <prestwoj@gmail.com>
To: iwd@lists.linux.dev
Cc: James Prestwood <prestwoj@gmail.com>
Subject: [PATCH v2 3/9] dpp-util: fail on duplicate values in URI
Date: Wed, 16 Apr 2025 10:33:39 -0700	[thread overview]
Message-ID: <20250416173345.136025-3-prestwoj@gmail.com> (raw)
In-Reply-To: <20250416173345.136025-1-prestwoj@gmail.com>

The MAC and version elements weren't super critical but the channel
and bootstrapping key elements would result in memory leaks if there
were duplicates.

This patch now will not allow duplicate elements in the URI.

Fixes: f7f602e1 ("dpp-util: add URI parsing")
---
 src/dpp-util.c | 13 +++++++++++++
 1 file changed, 13 insertions(+)

diff --git a/src/dpp-util.c b/src/dpp-util.c
index cfdedbdd..1986a5cc 100644
--- a/src/dpp-util.c
+++ b/src/dpp-util.c
@@ -1166,21 +1166,34 @@ struct dpp_uri_info *dpp_parse_uri(const char *uri)
 
 		switch (*pos) {
 		case 'C':
+			if (L_WARN_ON(info->freqs))
+				goto free_info;
+
 			info->freqs = dpp_parse_class_and_channel(pos + 2, len);
 			if (!info->freqs)
 				goto free_info;
 			break;
 		case 'M':
+			if (L_WARN_ON(!l_memeqzero(info->mac,
+							sizeof(info->mac))))
+				goto free_info;
+
 			ret = dpp_parse_mac(pos + 2, len, info->mac);
 			if (ret < 0)
 				goto free_info;
 			break;
 		case 'V':
+			if (L_WARN_ON(info->version != 0))
+				goto free_info;
+
 			ret = dpp_parse_version(pos + 2, len, &info->version);
 			if (ret < 0)
 				goto free_info;
 			break;
 		case 'K':
+			if (L_WARN_ON(info->boot_public))
+				goto free_info;
+
 			info->boot_public = dpp_parse_key(pos + 2, len);
 			if (!info->boot_public)
 				goto free_info;
-- 
2.34.1


  parent reply	other threads:[~2025-04-16 17:33 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-04-16 17:33 [PATCH v2 1/9] monitor: fix spelling Exausted -> Exhausted James Prestwood
2025-04-16 17:33 ` [PATCH v2 2/9] scan: fix out of bound array access for survey results James Prestwood
2025-04-16 17:33 ` James Prestwood [this message]
2025-04-16 17:33 ` [PATCH v2 4/9] unit: add test for duplicate URI elements James Prestwood
2025-04-16 17:33 ` [PATCH v2 5/9] monitor: add size check for interworking IE parsing James Prestwood
2025-04-16 17:33 ` [PATCH v2 6/9] storage: add length check in __storage_decrypt James Prestwood
2025-04-16 17:33 ` [PATCH v2 7/9] unit: add test-storage James Prestwood
2025-04-16 17:33 ` [PATCH v2 8/9] station: check return when advancing iterator James Prestwood
2025-04-16 17:33 ` [PATCH v2 9/9] eap-mschapv2: Fix leak of state->user on error path James Prestwood
2025-04-16 19:58 ` [PATCH v2 1/9] monitor: fix spelling Exausted -> Exhausted Denis Kenzior

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20250416173345.136025-3-prestwoj@gmail.com \
    --to=prestwoj@gmail.com \
    --cc=iwd@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox