Skip to content

blackbox: fix potential overlow/memory corruption#486

Merged
chrissie-c merged 1 commit intomainfrom
fix-log-overflow
Jun 5, 2023
Merged

blackbox: fix potential overlow/memory corruption#486
chrissie-c merged 1 commit intomainfrom
fix-log-overflow

Conversation

@chrissie-c
Copy link
Copy Markdown
Contributor

if the message was too long, then msg_len was added to the buffer size twice, thus causing potential data corruption (seen VERY rarely in the CI test - or, at least, I think it was this).

Also fix a double close() spotted by gcc13's -fanalyzer

if the message was too long, then msg_len was added to the
buffer size twice, thus causing potential data corruption
(seen VERY rarely in the CI test - or, at least, I think it was
this).

Also fix a double close() spotted by gcc13's -fanalyzer
Copy link
Copy Markdown
Member

@jfriesse jfriesse left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ACK. Nice to see gcc analyzer gets better than coverity ;)

@chrissie-c
Copy link
Copy Markdown
Contributor Author

retest this please

@chrissie-c chrissie-c merged commit 5862acb into main Jun 5, 2023
@chrissie-c chrissie-c deleted the fix-log-overflow branch June 5, 2023 08:51
bmwiedemann pushed a commit to bmwiedemann/openSUSE that referenced this pull request Jun 21, 2023
https://build.opensuse.org/request/show/1093859
by user yan_gao + dimstar_suse
- Update to version 2.0.7+20230607.06c8641 (v2.0.7):
- blackbox: fix potential overlow/memory corruption (gh#ClusterLabs/libqb#486)
- tests: allow -j to work (gh#ClusterLabs/libqb#485)
- strlcpy: avoid compiler warning from strncpy (gh#ClusterLabs/libqb#473)
- timer: Move state check to before time check (gh#ClusterLabs/libqb#479)
- ipc: Retry receiving credentials if the the message is short (gh#ClusterLabs/libqb#476, rh#2111711)
- lib: Fix some small bugs spotted by newest covscan (gh#ClusterLabs/libqb#471)
- doxygen2man: Fix function parameter alignment (gh#ClusterLabs/libqb#468) (forwarded request 1093858 from yan_gao)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants