projects
/
systemd
/
.git
/ commitdiff
commit
grep
author
committer
pickaxe
?
search:
re
summary
|
shortlog
|
log
|
commit
| commitdiff |
tree
raw
|
patch
| inline |
side by side
(parent:
cd740bd
)
util: another set of CVE-2021-4034 assert()s
author
Lennart Poettering
<lennart@poettering.net>
Tue, 1 Feb 2022 11:06:21 +0000
(12:06 +0100)
committer
Luca Boccassi
<bluca@debian.org>
Mon, 14 Feb 2022 22:02:47 +0000
(22:02 +0000)
It's a good idea that we validate argc/argv when we are supposed to
store them away.
(cherry picked from commit
007e03b284e8ffc0b92edb2122cd9d2d16f049ef
)
src/basic/util.h
patch
|
blob
|
history
diff --git
a/src/basic/util.h
b/src/basic/util.h
index 94804f28e3f7256afb282a4b6162e931d984f1e8..68ae3b51e0e0a897ee02b8661ca95589141459f1 100644
(file)
--- a/
src/basic/util.h
+++ b/
src/basic/util.h
@@
-9,6
+9,12
@@
extern int saved_argc;
extern char **saved_argv;
static inline void save_argc_argv(int argc, char **argv) {
+
+ /* Protect against CVE-2021-4034 style attacks */
+ assert_se(argc > 0);
+ assert_se(argv);
+ assert_se(argv[0]);
+
saved_argc = argc;
saved_argv = argv;
}