Page MenuHomeFreeBSD

libutil: avoid an out-of-bounds read in trimdomain(3)
ClosedPublic

Authored by kevans on Jan 9 2026, 5:00 PM.
Tags
None
Referenced Files
Unknown Object (File)
Sat, Jun 20, 1:05 AM
Unknown Object (File)
Tue, Jun 16, 8:29 AM
Unknown Object (File)
May 24 2026, 2:18 AM
Unknown Object (File)
May 22 2026, 2:31 PM
Unknown Object (File)
May 22 2026, 3:04 AM
Unknown Object (File)
May 22 2026, 12:37 AM
Unknown Object (File)
May 17 2026, 7:43 PM
Unknown Object (File)
May 17 2026, 7:42 PM
Subscribers

Details

Summary

memchr(3) will happily believe we've passed in a valid object, but
hostsize could easily exceed the bounds of fullhost. Clamp it down to
the string size to be safe and avoid UB.

Sponsored by: Klara, Inc.

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Skipped
Unit
Tests Skipped
Build Status
Buildable 69766
Build 66649: arc lint + arc unit