scsi_id: null-terminate serial after append_vendor_model

append_vendor_model() uses memcpy() to write VENDOR_LENGTH +
MODEL_LENGTH bytes without null-terminating. While the caller
zeroes the buffer beforehand, Coverity cannot trace this. Add
explicit null termination so the subsequent strlen() is provably
safe.

CID#1469706

Follow-up for 86fd0337c6
This commit is contained in:
Luca Boccassi
2026-04-07 23:08:29 +01:00
parent 874fbb870c
commit c9da918805

View File

@@ -491,9 +491,14 @@ static int check_fill_0x83_id(struct scsi_id_device *dev_scsi,
* this differs from SCSI_ID_T10_VENDOR, where the vendor is
* included in the identifier.
*/
if (id_search->id_type == SCSI_ID_VENDOR_SPECIFIC)
if (id_search->id_type == SCSI_ID_VENDOR_SPECIFIC) {
if (append_vendor_model(dev_scsi, serial + 1) < 0)
return 1;
/* append_vendor_model() uses memcpy() without null-terminating.
* The buffer was zeroed by the caller, but ensure the string is
* explicitly terminated for strlen() below. */
serial[1 + VENDOR_LENGTH + MODEL_LENGTH] = '\0';
}
i = 4; /* offset to the start of the identifier */
s = j = strlen(serial);