scsi_id: use strscpy instead of strncpy for wwn fields

strncpy does not null-terminate the destination buffer if the source
string is longer than the count parameter. Since wwn and
wwn_vendor_extension are char[17] and we copy up to 16 bytes, there's
a risk of missing null termination. Use strscpy which always
null-terminates.

CID#1469706

Follow-up for 4e9fdfccbd

(cherry picked from commit 86fd0337c6)
(cherry picked from commit bf5951ea7d)
This commit is contained in:
Luca Boccassi
2026-03-28 19:35:36 +00:00
parent a8c4af7997
commit d8f7f71200

View File

@@ -20,6 +20,7 @@
#include "scsi.h"
#include "scsi_id.h"
#include "string-util.h"
#include "strxcpyx.h"
#include "time-util.h"
/*
@@ -518,9 +519,9 @@ static int check_fill_0x83_id(struct scsi_id_device *dev_scsi,
strcpy(serial_short, serial + s);
if (id_search->id_type == SCSI_ID_NAA && wwn != NULL) {
strncpy(wwn, serial + s, 16);
strscpy(wwn, 17, serial + s);
if (wwn_vendor_extension)
strncpy(wwn_vendor_extension, serial + s + 16, 16);
strscpy(wwn_vendor_extension, 17, serial + s + 16);
}
return 0;