fix(httpd): validate buf_len in httpd_req_get_url_query_str_ptr()

This commit is contained in:
Ashish Sharma
2026-06-16 17:59:26 +08:00
parent 3c64eea401
commit 9f84a7c3e3
2 changed files with 8 additions and 6 deletions
@@ -1065,17 +1065,17 @@ esp_err_t httpd_req_get_url_query_str(httpd_req_t *r, char *buf, size_t buf_len)
* algorithm needs to be applied. * algorithm needs to be applied.
* - This API is supposed to be called only from the context of * - This API is supposed to be called only from the context of
* a URI handler where httpd_req_t* request pointer is valid * a URI handler where httpd_req_t* request pointer is valid
* - The byte range between buf and buf_len should only be used withing * - The byte range between buf and buf_len should only be used within
* the URI handler and not after since it will lead to use after free * the URI handler and not after since it will lead to use after free
* errors * errors
* *
* @param[in] r The request being responded to * @param[in] r The request being responded to
* @param[out] buf Pointer to a pointer that should be updated to the begin of * @param[out] buf Pointer to a pointer that should be updated to the beginning of
* the buffer * the query string within the request URL
* @param[out] buf_len Pointer of length of output buffer * @param[out] buf_len Pointer to a length that will be updated with the query length
* *
* @return * @return
* - ESP_OK : Query is found in the request URL and copied to buffer * - ESP_OK : Query found; *buf points to the query string and *buf_len holds its length
* - ESP_FAIL : uri is empty * - ESP_FAIL : uri is empty
* - ESP_ERR_NOT_FOUND : Query not found * - ESP_ERR_NOT_FOUND : Query not found
* - ESP_ERR_INVALID_ARG : Null arguments * - ESP_ERR_INVALID_ARG : Null arguments
+3 -1
View File
@@ -1016,7 +1016,9 @@ esp_err_t httpd_req_get_url_query_str(httpd_req_t *r, char *buf, size_t buf_len)
esp_err_t httpd_req_get_url_query_str_ptr(httpd_req_t *r, const char **buf, size_t *buf_len) esp_err_t httpd_req_get_url_query_str_ptr(httpd_req_t *r, const char **buf, size_t *buf_len)
{ {
if (r == NULL || buf == NULL) { /* buf_len is an output pointer that is dereferenced below, so it must be
* validated along with the other arguments to avoid a NULL write */
if (r == NULL || buf == NULL || buf_len == NULL) {
return ESP_ERR_INVALID_ARG; return ESP_ERR_INVALID_ARG;
} }