From: Phil Sutter Date: Thu, 27 Jun 2024 08:18:17 +0000 (+0200) Subject: lib: ipset: Avoid 'argv' array overstepping X-Git-Tag: v7.23~9 X-Git-Url: http://git.ipfire.org/?a=commitdiff_plain;h=851cb04ffee5040f1e0063f77c3fe9bc6245e0fb;p=thirdparty%2Fipset.git lib: ipset: Avoid 'argv' array overstepping The maximum accepted value for 'argc' is MAX_ARGS which matches 'argv' array size. The maximum allowed array index is therefore argc-1. This fix will leave items in argv non-NULL-terminated, so explicitly NULL the formerly last entry after shifting. Looks like a day-1 bug. Interestingly, this neither triggered ASAN nor valgrind. Yet adding debug output printing argv entries being copied did. Fixes: 1e6e8bd9a62aa ("Third stage to ipset-5") Signed-off-by: Phil Sutter Signed-off-by: Jozsef Kadlecsik --- diff --git a/lib/ipset.c b/lib/ipset.c index c910d88..3bf1c5f 100644 --- a/lib/ipset.c +++ b/lib/ipset.c @@ -343,9 +343,9 @@ ipset_shift_argv(int *argc, char *argv[], int from) assert(*argc >= from + 1); - for (i = from + 1; i <= *argc; i++) + for (i = from + 1; i < *argc; i++) argv[i-1] = argv[i]; - (*argc)--; + argv[--(*argc)] = NULL; return; }