mirror of
https://github.com/systemd/systemd.git
synced 2026-08-08 09:01:02 +00:00
scsi_id: null-terminate serial after append_vendor_model
append_vendor_model() uses memcpy() to write VENDOR_LENGTH +
MODEL_LENGTH bytes without null-terminating. While the caller
zeroes the buffer beforehand, Coverity cannot trace this. Add
explicit null termination so the subsequent strlen() is provably
safe.
CID#1469706
Follow-up for 86fd0337c6
This commit is contained in:
@@ -491,9 +491,14 @@ static int check_fill_0x83_id(struct scsi_id_device *dev_scsi,
|
||||
* this differs from SCSI_ID_T10_VENDOR, where the vendor is
|
||||
* included in the identifier.
|
||||
*/
|
||||
if (id_search->id_type == SCSI_ID_VENDOR_SPECIFIC)
|
||||
if (id_search->id_type == SCSI_ID_VENDOR_SPECIFIC) {
|
||||
if (append_vendor_model(dev_scsi, serial + 1) < 0)
|
||||
return 1;
|
||||
/* append_vendor_model() uses memcpy() without null-terminating.
|
||||
* The buffer was zeroed by the caller, but ensure the string is
|
||||
* explicitly terminated for strlen() below. */
|
||||
serial[1 + VENDOR_LENGTH + MODEL_LENGTH] = '\0';
|
||||
}
|
||||
|
||||
i = 4; /* offset to the start of the identifier */
|
||||
s = j = strlen(serial);
|
||||
|
||||
Reference in New Issue
Block a user