fix(protocomm): prevent out-of-bounds write in console line buffer

The console transport read loop passed &linebuf[i] to uart_read_bytes()
before checking i < LINE_BUF_SIZE, so a line of LINE_BUF_SIZE or more
bytes without a terminator wrote one byte past the 256-byte linebuf
stack array.

Gate the read on the bounds check and reserve the final byte for the NUL
terminator (LINE_BUF_SIZE - 1), so the buffer handed to esp_console_run()
stays terminated even when an overlong line is truncated.

Closes https://github.com/espressif/esp-idf/issues/18638

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
Andrii Anoshyn
2026-06-05 17:33:59 +08:00
committed by Ashish Sharma
co-authored by Claude Opus 4.7
parent f0d98bebfe
commit 12721c5c8b
@@ -94,7 +94,7 @@ static void protocomm_console_task(void *arg)
}
}
if (event.type == UART_DATA) {
while (uart_read_bytes(uart_num, (uint8_t *) &linebuf[i], 1, 0) && (i < LINE_BUF_SIZE)) {
while ((i < LINE_BUF_SIZE - 1) && uart_read_bytes(uart_num, (uint8_t *) &linebuf[i], 1, 0)) {
if (linebuf[i] == '\r') {
uart_write_bytes(uart_num, "\r\n", 2);
} else {
@@ -106,7 +106,7 @@ static void protocomm_console_task(void *arg)
if ((i > 0) && (linebuf[i-1] == '\r')) {
break;
}
} while (i < LINE_BUF_SIZE);
} while (i < LINE_BUF_SIZE - 1);
if (stopped()) {
break;
}