mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-02 11:10:54 +03:00
fix(esp_http_server): close UAF/double-free, buffer underflows, and OOB read
This commit is contained in:
@@ -895,7 +895,9 @@ bool httpd_validate_req_ptr(httpd_req_t *r)
|
|||||||
/* Helper function to get a URL query tag from a query string of the type param1=val1¶m2=val2 */
|
/* Helper function to get a URL query tag from a query string of the type param1=val1¶m2=val2 */
|
||||||
esp_err_t httpd_query_key_value(const char *qry_str, const char *key, char *val, size_t val_size)
|
esp_err_t httpd_query_key_value(const char *qry_str, const char *key, char *val, size_t val_size)
|
||||||
{
|
{
|
||||||
if (qry_str == NULL || key == NULL || val == NULL) {
|
/* Reject a zero-size output buffer: val_size - 1 below would underflow to SIZE_MAX,
|
||||||
|
* defeating the truncation check and overflowing the caller's buffer (CWE-191/CWE-787). */
|
||||||
|
if (qry_str == NULL || key == NULL || val == NULL || val_size == 0) {
|
||||||
return ESP_ERR_INVALID_ARG;
|
return ESP_ERR_INVALID_ARG;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -978,7 +980,9 @@ size_t httpd_req_get_url_query_len(httpd_req_t *r)
|
|||||||
|
|
||||||
esp_err_t httpd_req_get_url_query_str(httpd_req_t *r, char *buf, size_t buf_len)
|
esp_err_t httpd_req_get_url_query_str(httpd_req_t *r, char *buf, size_t buf_len)
|
||||||
{
|
{
|
||||||
if (r == NULL || buf == NULL) {
|
/* Reject a zero-size output buffer: buf_len - 1 below would underflow to SIZE_MAX,
|
||||||
|
* defeating the truncation check and overflowing the caller's buffer (CWE-191/CWE-787). */
|
||||||
|
if (r == NULL || buf == NULL || buf_len == 0) {
|
||||||
return ESP_ERR_INVALID_ARG;
|
return ESP_ERR_INVALID_ARG;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -1171,7 +1175,10 @@ esp_err_t httpd_req_get_hdr_value_str_ptr(httpd_req_t *r, const char *field, con
|
|||||||
/* Helper function to get a cookie value from a cookie string of the type "cookie1=val1; cookie2=val2" */
|
/* Helper function to get a cookie value from a cookie string of the type "cookie1=val1; cookie2=val2" */
|
||||||
esp_err_t static httpd_cookie_key_value(const char *cookie_str, const char *key, char *val, size_t *val_size)
|
esp_err_t static httpd_cookie_key_value(const char *cookie_str, const char *key, char *val, size_t *val_size)
|
||||||
{
|
{
|
||||||
if (cookie_str == NULL || key == NULL || val == NULL) {
|
/* Reject a NULL or zero-size output buffer: *val_size - 1 below would underflow to
|
||||||
|
* SIZE_MAX, defeating the truncation check and overflowing the caller's buffer
|
||||||
|
* (CWE-191/CWE-787). val_size is also dereferenced below, so it must be non-NULL. */
|
||||||
|
if (cookie_str == NULL || key == NULL || val == NULL || val_size == NULL || *val_size == 0) {
|
||||||
return ESP_ERR_INVALID_ARG;
|
return ESP_ERR_INVALID_ARG;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -1295,6 +1302,10 @@ esp_err_t httpd_get_raw_req_data(httpd_req_t *req, char *buf, size_t buf_len)
|
|||||||
return ESP_ERR_INVALID_ARG;
|
return ESP_ERR_INVALID_ARG;
|
||||||
}
|
}
|
||||||
struct httpd_req_aux *ra = req->aux;
|
struct httpd_req_aux *ra = req->aux;
|
||||||
memcpy(buf, ra->scratch, buf_len);
|
/* The caller controls buf_len; a value larger than the valid scratch data would read
|
||||||
|
* past the scratch allocation (CWE-125). Clamp to scratch_cur_size. Callers should query
|
||||||
|
* the available length with httpd_get_raw_req_data_len() before calling this. */
|
||||||
|
size_t copy_len = MIN(buf_len, ra->scratch_cur_size);
|
||||||
|
memcpy(buf, ra->scratch, copy_len);
|
||||||
return ESP_OK;
|
return ESP_OK;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -159,6 +159,7 @@ esp_err_t httpd_register_uri_handler(httpd_handle_t handle,
|
|||||||
if (hd->hd_calls[i]->uri == NULL) {
|
if (hd->hd_calls[i]->uri == NULL) {
|
||||||
/* Failed to allocate memory */
|
/* Failed to allocate memory */
|
||||||
free(hd->hd_calls[i]);
|
free(hd->hd_calls[i]);
|
||||||
|
hd->hd_calls[i] = NULL;
|
||||||
return ESP_ERR_HTTPD_ALLOC_MEM;
|
return ESP_ERR_HTTPD_ALLOC_MEM;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -181,6 +182,7 @@ esp_err_t httpd_register_uri_handler(httpd_handle_t handle,
|
|||||||
/* Failed to allocate memory */
|
/* Failed to allocate memory */
|
||||||
free((void *)hd->hd_calls[i]->uri);
|
free((void *)hd->hd_calls[i]->uri);
|
||||||
free(hd->hd_calls[i]);
|
free(hd->hd_calls[i]);
|
||||||
|
hd->hd_calls[i] = NULL;
|
||||||
return ESP_ERR_HTTPD_ALLOC_MEM;
|
return ESP_ERR_HTTPD_ALLOC_MEM;
|
||||||
}
|
}
|
||||||
} else {
|
} else {
|
||||||
|
|||||||
Reference in New Issue
Block a user