From bb5f79871f6877dec1d44e18f4f627d3f529742c Mon Sep 17 00:00:00 2001 From: Kamalesh Babulal Date: Wed, 8 Mar 2023 20:56:24 +0530 Subject: [PATCH] wrapper: fix segfault in cgroup_get_value_bool() The second and third arguments passed to cgroup_get_value_bool() are of type pointers and the user might pass NULL in place of one or both of the arguments, causing a segfault. The reason is, argument values are used without checks, fix it by checking for NULL pointers before proceeding. Reproducer: ----------- #include #include int main(void) { struct cgroup_controller *cgc; struct cgroup *cgrp; int ret; ret = cgroup_init(); if (ret) exit(1); cgrp = cgroup_new_cgroup("fuzzer"); if (!cgrp) exit(1); cgc = cgroup_add_controller(cgrp, "cpuset"); if (!cgc) exit(1); ret = cgroup_add_value_string(cgc, "cpuset.cpu_exclusive", "0"); if (ret) exit (1); cgroup_get_value_bool(cgc, "cpuset.cpu_exclusive", NULL); //should not reach here return 0; } Signed-off-by: Kamalesh Babulal Signed-off-by: Tom Hromatka (cherry picked from commit b701e7de9b9d93aaf2d1cc03f483c7229e6239c3) --- src/wrapper.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/wrapper.c b/src/wrapper.c index c87cc1e8..5d8b0023 100644 --- a/src/wrapper.c +++ b/src/wrapper.c @@ -575,7 +575,7 @@ int cgroup_get_value_bool(struct cgroup_controller *controller, const char *name { int i; - if (!controller) + if (!controller || !name || !value) return ECGINVAL; for (i = 0; i < controller->index; i++) { -- 2.47.2