mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-02 11:10:54 +03:00
fix(protocomm): prevent out-of-bounds write in console line buffer
The console transport read loop passed &linebuf[i] to uart_read_bytes() before checking i < LINE_BUF_SIZE, so a line of LINE_BUF_SIZE or more bytes without a terminator wrote one byte past the 256-byte linebuf stack array. Gate the read on the bounds check and reserve the final byte for the NUL terminator (LINE_BUF_SIZE - 1), so the buffer handed to esp_console_run() stays terminated even when an overlong line is truncated. Closes https://github.com/espressif/esp-idf/issues/18638 Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
committed by
Ashish Sharma
co-authored by
Claude Opus 4.7
parent
f0d98bebfe
commit
12721c5c8b
@@ -94,7 +94,7 @@ static void protocomm_console_task(void *arg)
|
||||
}
|
||||
}
|
||||
if (event.type == UART_DATA) {
|
||||
while (uart_read_bytes(uart_num, (uint8_t *) &linebuf[i], 1, 0) && (i < LINE_BUF_SIZE)) {
|
||||
while ((i < LINE_BUF_SIZE - 1) && uart_read_bytes(uart_num, (uint8_t *) &linebuf[i], 1, 0)) {
|
||||
if (linebuf[i] == '\r') {
|
||||
uart_write_bytes(uart_num, "\r\n", 2);
|
||||
} else {
|
||||
@@ -106,7 +106,7 @@ static void protocomm_console_task(void *arg)
|
||||
if ((i > 0) && (linebuf[i-1] == '\r')) {
|
||||
break;
|
||||
}
|
||||
} while (i < LINE_BUF_SIZE);
|
||||
} while (i < LINE_BUF_SIZE - 1);
|
||||
if (stopped()) {
|
||||
break;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user