From 18ec8de5d043ef09506f488363b9b411a44d4f96 Mon Sep 17 00:00:00 2001 From: Andrii Anoshyn Date: Fri, 22 May 2026 22:18:59 +0300 Subject: [PATCH] fix(protocomm): prevent out-of-bounds write in console line buffer The console transport read loop passed &linebuf[i] to uart_read_bytes() before checking i < LINE_BUF_SIZE, so a line of LINE_BUF_SIZE or more bytes without a terminator wrote one byte past the 256-byte linebuf stack array. Gate the read on the bounds check and reserve the final byte for the NUL terminator (LINE_BUF_SIZE - 1), so the buffer handed to esp_console_run() stays terminated even when an overlong line is truncated. Closes https://github.com/espressif/esp-idf/issues/18638 Co-Authored-By: Claude Opus 4.7 (1M context) --- components/protocomm/src/transports/protocomm_console.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/components/protocomm/src/transports/protocomm_console.c b/components/protocomm/src/transports/protocomm_console.c index d09386f0ea7..ac049a7af03 100644 --- a/components/protocomm/src/transports/protocomm_console.c +++ b/components/protocomm/src/transports/protocomm_console.c @@ -94,7 +94,7 @@ static void protocomm_console_task(void *arg) } } if (event.type == UART_DATA) { - while (uart_read_bytes(uart_num, (uint8_t *) &linebuf[i], 1, 0) && (i < LINE_BUF_SIZE)) { + while ((i < LINE_BUF_SIZE - 1) && uart_read_bytes(uart_num, (uint8_t *) &linebuf[i], 1, 0)) { if (linebuf[i] == '\r') { uart_write_bytes(uart_num, "\r\n", 2); } else { @@ -106,7 +106,7 @@ static void protocomm_console_task(void *arg) if ((i > 0) && (linebuf[i-1] == '\r')) { break; } - } while (i < LINE_BUF_SIZE); + } while (i < LINE_BUF_SIZE - 1); if (stopped()) { break; }