-
Notifications
You must be signed in to change notification settings - Fork 58.3k
Potential Vulnerability: Missing Null-Termination in ecryptfs_fill_auth_tok #1259
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
…uth_tok-with-null-termination Fix missing null terminator in ecryptfs auth token
|
Hi @DiamondGotCat! Thanks for your contribution to the Linux kernel! Linux kernel development happens on mailing lists, rather than on GitHub - this GitHub repository is a read-only mirror that isn't used for accepting contributions. So that your change can become part of Linux, please email it to us as a patch. Sending patches isn't quite as simple as sending a pull request, but fortunately it is a well documented process. Here's what to do:
How do I format my contribution?The Linux kernel community is notoriously picky about how contributions are formatted and sent. Fortunately, they have documented their expectations. Firstly, all contributions need to be formatted as patches. A patch is a plain text document showing the change you want to make to the code, and documenting why it is a good idea. You can create patches with Secondly, patches need 'commit messages', which is the human-friendly documentation explaining what the change is and why it's necessary. Thirdly, changes have some technical requirements. There is a Linux kernel coding style, and there are licensing requirements you need to comply with. Both of these are documented in the Submitting Patches documentation that is part of the kernel. Note that you will almost certainly have to modify your existing git commits to satisfy these requirements. Don't worry: there are many guides on the internet for doing this. Where do I send my contribution?The Linux kernel is composed of a number of subsystems. These subsystems are maintained by different people, and have different mailing lists where they discuss proposed changes. If you don't already know what subsystem your change belongs to, the
Make sure that your list of recipients includes a mailing list. If you can't find a more specific mailing list, then LKML - the Linux Kernel Mailing List - is the place to send your patches. It's not usually necessary to subscribe to the mailing list before you send the patches, but if you're interested in kernel development, subscribing to a subsystem mailing list is a good idea. (At this point, you probably don't need to subscribe to LKML - it is a very high traffic list with about a thousand messages per day, which is often not useful for beginners.) How do I send my contribution?Use For more information about using How do I get help if I'm stuck?Firstly, don't get discouraged! There are an enormous number of resources on the internet, and many kernel developers who would like to see you succeed. Many issues - especially about how to use certain tools - can be resolved by using your favourite internet search engine. If you can't find an answer, there are a few places you can turn:
If you get really, really stuck, you could try the owners of this bot, @daxtens and @ajdlinux. Please be aware that we do have full-time jobs, so we are almost certainly the slowest way to get answers! I sent my patch - now what?You wait. You can check that your email has been received by checking the mailing list archives for the mailing list you sent your patch to. Messages may not be received instantly, so be patient. Kernel developers are generally very busy people, so it may take a few weeks before your patch is looked at. Then, you keep waiting. Three things may happen:
Further information
Happy hacking! This message was posted by a bot - if you have any questions or suggestions, please talk to my owners, @ajdlinux and @daxtens, or raise an issue at https://github.com/ajdlinux/KernelPRBot. |
|
I don't know enough about using |
Overview
The function
ecryptfs_fill_auth_tok()populates anecryptfs_auth_tokstructure from a user-supplied key descriptor. It usesstrncpy()to copy the signature, which may omit the terminating'\0'when the input length matchesECRYPTFS_PASSWORD_SIG_SIZE(16 bytes). Without explicit termination, subsequent operations that treat this buffer as a C string may read uninitialized memory or leak information.Relevant code excerpt:
In the
ecryptfs_passwordstructure, thesignaturefield provides space for the extra byte:ECRYPTFS_PASSWORD_SIG_SIZEis defined as 16 (ECRYPTFS_SIG_SIZE_HEX):Risk
If the null terminator is absent and another routine copies or manipulates the signature assuming a properly terminated string, it may read past the end of valid data. This can lead to:
Mitigation
Explicitly writing a null terminator after the
strncpy()call ensures the signature buffer is always valid as a C string:This assignment is present in the current code, which correctly mitigates the risk.
Conclusion
The vulnerable pattern arises when using
strncpy()without guaranteeing null termination. Ensuring the signature is explicitly terminated prevents accidental reads of uninitialized memory. The repository version already contains the necessary fix, but older versions lacking this statement may be susceptible.NOTE
I discovered this vulnerability in the Codex published by OpenAI and have confirmed that the vulnerability information is in fact correct.
If it is incorrect, please reject this pull request.