If a "uuid:" label is set in the petitboot,bootdevs or petitboot,bootdev
parameters without a matching UUID, the UUID is unintentionally accepted
and set to NULL. This can cause a segfault in nc-config when device
UUIDs are compared against the autoboot option. Instead treat options
like this as malformed.
Signed-off-by: Samuel Mendoza-Jonas <sam@mendozajonas.com>
if (!strncmp(*pos, "uuid:", strlen("uuid:"))) {
prefix = strlen("uuid:");
opt->boot_type = BOOT_DEVICE_UUID;
if (!strncmp(*pos, "uuid:", strlen("uuid:"))) {
prefix = strlen("uuid:");
opt->boot_type = BOOT_DEVICE_UUID;
} else if (!strncmp(*pos, "mac:", strlen("mac:"))) {
prefix = strlen("mac:");
opt->boot_type = BOOT_DEVICE_UUID;
} else if (!strncmp(*pos, "mac:", strlen("mac:"))) {
prefix = strlen("mac:");
opt->boot_type = BOOT_DEVICE_UUID;
} else {
type = find_device_type(*pos);
if (type != DEVICE_TYPE_UNKNOWN) {
} else {
type = find_device_type(*pos);
if (type != DEVICE_TYPE_UNKNOWN) {
if (delim)
len = (int)(delim - *pos) - prefix;
else
if (delim)
len = (int)(delim - *pos) - prefix;
else
+ len = strlen(*pos) - prefix;
- opt->uuid = talloc_strndup(ctx, *pos + prefix, len);
+ if (len) {
+ opt->uuid = talloc_strndup(ctx, *pos + prefix, len);
+ rc = 0;
+ }
}
/* Always advance pointer to next option or end */
}
/* Always advance pointer to next option or end */
unsigned int n_new = 0;
const char *val;
bool conflict;
unsigned int n_new = 0;
const char *val;
bool conflict;
/* Check for old-style bootdev */
val = get_param(platform, "petitboot,bootdev");
if (val && strlen(val)) {
pos = talloc_strdup(config, val);
if (!strncmp(val, "uuid:", strlen("uuid:")))
/* Check for old-style bootdev */
val = get_param(platform, "petitboot,bootdev");
if (val && strlen(val)) {
pos = talloc_strdup(config, val);
if (!strncmp(val, "uuid:", strlen("uuid:")))
- old_dev = talloc_strdup(config,
- val + strlen("uuid:"));
else if (!strncmp(val, "mac:", strlen("mac:")))
else if (!strncmp(val, "mac:", strlen("mac:")))
- old_dev = talloc_strdup(config,
- val + strlen("mac:"));
+ len = strlen("mac:");
+ /* Make sure someone hasn't set a blank UUID */
+ if (len && *(val + len) != '\0')
+ old_dev = talloc_strdup(config, val + len);
}
/* Check for ordered bootdevs */
}
/* Check for ordered bootdevs */