The second argument passed to cgroup_set_value_bool() is of type
char * and the user might pass NULL in the place of the argument,
causing a segfault. The reason is, argument values are used without
checks, fix it by checking for NULL pointers before proceeding.
Reproducer:
----------
#include <stdlib.h>
#include <libcgroup.h>
int main(void)
{
struct cgroup_controller *cgc;
struct cgroup *cgrp;
int ret;
ret = cgroup_init();
if (ret)
exit(1);
cgrp = cgroup_new_cgroup("fuzzer");
if (!cgrp)
exit(1);
cgc = cgroup_add_controller(cgrp, "cpuset");
if (!cgc)
exit(1);
ret = cgroup_add_value_string(cgc, "cpuset.cpu_exclusive", "0");
if (ret)
exit (1);
cgroup_set_value_bool(cgc, NULL, 0);
//should not reach here
return 0;
}
Signed-off-by: Kamalesh Babulal <kamalesh.babulal@oracle.com>
Signed-off-by: Tom Hromatka <tom.hromatka@oracle.com>
(cherry picked from commit
6b5762ceaca18122b8d7a233b1d3453945594d32)
int ret;
int i;
- if (!controller)
+ if (!controller || !name)
return ECGINVAL;
for (i = 0; i < controller->index; i++) {