]> CyberLeo.Net >> Repos - FreeBSD/FreeBSD.git/commit
elf_note_prpsinfo: handle more failures from proc_getargv()
authorKonstantin Belousov <kib@FreeBSD.org>
Fri, 3 Jun 2022 08:21:23 +0000 (11:21 +0300)
committerMark Johnston <markj@FreeBSD.org>
Tue, 9 Aug 2022 19:44:45 +0000 (15:44 -0400)
commit00d17cf342cd9f4f8fd1dcd79c8caec359145532
tree8dd4f35013e04cb9556df1921eb8748a69b8d8a5
parent6b6367ba8fd2b29de29ce08e7432291e807c3bc0
elf_note_prpsinfo: handle more failures from proc_getargv()

Resulting sbuf_len() from proc_getargv() might return 0 if user mangled
ps_strings enough. Also, sbuf_len() API contract is to return -1 if the
buffer overflowed. The later should not occur because get_ps_strings()
checks for catenated length, but check for this subtle detail explicitly
as well to be more resilent.

The end result is that p_comm is used in this situations.

Approved by: so
Security: FreeBSD-SA-22:09.elf
Reported by: Josef 'Jeff' Sipek <jeffpc@josefsipek.net>
Reviewed by: delphij, markj
admbugs: 988
Sponsored by: The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D35391
sys/compat/linux/linux_elf.c
sys/kern/imgact_elf.c