Buffer overflow in cupsSideChannelSNMPGet()
Maintainers usually reply within 1 day
@michaelrsweet is already working on this.
Since Sep 24, 2026.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 45/100
Research direction
The bug is in cups/sidechannel.c lines 322-331 in cupsSideChannelSNMPGet() and a similar function cupsSideChannelSNMPWalk(). Start by reading the sidechannel.c file to understand the buffer handling and the _cupsBufferGet() function. The fix involves checking that the null terminator is within real_datalen before using strlen, and correcting the size check in SNMPWalk. Test by building CUPS and running any sidechannel-related tests.
Written by the indexing model from the issue text.
Description
Problem:
cupsSideChannelSNMPGet() takes the OID length from strlen(real_data) + 1 without checking that the nul terminator is inside the real_datalen bytes the backend actually sent, so strlen() runs into the uninitialised tail of the _cupsBufferGet() buffer. real_datalen then goes negative, the "(real_datalen + 1) > *datalen" check passes for any caller buffer, and memcpy() gets (size_t)real_datalen as its size.
https://github.com/OpenPrinting/cups/blob/e72b70245fbe81242a959be0ed1cbfc9dbefcd9a/cups/sidechannel.c#L322-L331
cupsSideChannelSNMPWalk() has the same flaw and its guard against it, "if ((size_t)real_datalen < sizeof(real_data))", measures a char pointer instead of the 65540 byte buffer, so it only fires when real_datalen is below 8.
Found by Linux Verification Center (portal.linuxtesting.ru) with SVACE.
Reporter: Pavel Nekrasov ([email protected]).
- Dominant language
- C
- Stars
- 1.8k
- Forks
- 331
- Avg merge
- 15h 28m
- Merged PRs (30d)
- 5
Getting set up
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from OpenPrinting/cups
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
OpenPrinting/cups#1721 ·
Maintainers usually reply within 1 day
-
Difficulty 4/5 3-5 days Newbie friendliness 55/100
OpenPrinting/cups#1724 ·
Maintainers usually reply within 1 day
-
Integer overflow in httpGetDateTime()Possibly taken @michaelrsweet claimed this 3 days ago. Openbug priority-low
Difficulty 3/5 1-2 days Newbie friendliness 65/100
OpenPrinting/cups#1717 · 1 assignee ·
Maintainers usually reply within 1 day
-
Integer overflow in show_supplies()Possibly taken @michaelrsweet claimed this 3 days ago. Openenhancement investigating
Difficulty 3/5 1-2 days Newbie friendliness 65/100
OpenPrinting/cups#1715 · 1 comment · 1 assignee ·
Maintainers usually reply within 1 day
-
Difficulty 4/5 3-5 days Newbie friendliness 38/100
OpenPrinting/cups#1707 · 4 comments ·
Maintainers usually reply within 1 day
All issues in OpenPrinting/cups
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
ARM-software/sysarch-acs#556 · 1 comment ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day
-
bug needs triage
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
netdata/netdata#24062 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 76/100