fix(esp_http_server): close UAF/double-free and query/cookie buffer underflows

This commit is contained in:
Ashish Sharma
2026-08-25 12:02:05 +08:00
parent 7c2e4b2a58
commit 370cbcaff9
2 changed files with 12 additions and 3 deletions
+10 -3
View File
@@ -888,7 +888,9 @@ bool httpd_validate_req_ptr(httpd_req_t *r)
/* Helper function to get a URL query tag from a query string of the type param1=val1&param2=val2 */
esp_err_t httpd_query_key_value(const char *qry_str, const char *key, char *val, size_t val_size)
{
if (qry_str == NULL || key == NULL || val == NULL) {
/* Reject a zero-size output buffer: val_size - 1 below would underflow to SIZE_MAX,
* defeating the truncation check and overflowing the caller's buffer (CWE-191/CWE-787). */
if (qry_str == NULL || key == NULL || val == NULL || val_size == 0) {
return ESP_ERR_INVALID_ARG;
}
@@ -971,7 +973,9 @@ size_t httpd_req_get_url_query_len(httpd_req_t *r)
esp_err_t httpd_req_get_url_query_str(httpd_req_t *r, char *buf, size_t buf_len)
{
if (r == NULL || buf == NULL) {
/* Reject a zero-size output buffer: buf_len - 1 below would underflow to SIZE_MAX,
* defeating the truncation check and overflowing the caller's buffer (CWE-191/CWE-787). */
if (r == NULL || buf == NULL || buf_len == 0) {
return ESP_ERR_INVALID_ARG;
}
@@ -1130,7 +1134,10 @@ esp_err_t httpd_req_get_hdr_value_str(httpd_req_t *r, const char *field, char *v
/* Helper function to get a cookie value from a cookie string of the type "cookie1=val1; cookie2=val2" */
esp_err_t static httpd_cookie_key_value(const char *cookie_str, const char *key, char *val, size_t *val_size)
{
if (cookie_str == NULL || key == NULL || val == NULL) {
/* Reject a NULL or zero-size output buffer: *val_size - 1 below would underflow to
* SIZE_MAX, defeating the truncation check and overflowing the caller's buffer
* (CWE-191/CWE-787). val_size is also dereferenced below, so it must be non-NULL. */
if (cookie_str == NULL || key == NULL || val == NULL || val_size == NULL || *val_size == 0) {
return ESP_ERR_INVALID_ARG;
}
@@ -159,6 +159,7 @@ esp_err_t httpd_register_uri_handler(httpd_handle_t handle,
if (hd->hd_calls[i]->uri == NULL) {
/* Failed to allocate memory */
free(hd->hd_calls[i]);
hd->hd_calls[i] = NULL;
return ESP_ERR_HTTPD_ALLOC_MEM;
}
@@ -181,6 +182,7 @@ esp_err_t httpd_register_uri_handler(httpd_handle_t handle,
/* Failed to allocate memory */
free((void *)hd->hd_calls[i]->uri);
free(hd->hd_calls[i]);
hd->hd_calls[i] = NULL;
return ESP_ERR_HTTPD_ALLOC_MEM;
}
} else {