Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Buffer overflow in cupsSideChannelSNMPGet()

Open
#1,719 0 comments 0 reactions 1 assignee View on GitHub

Maintainers usually reply within 1 day

@michaelrsweet is already working on this.

Since Sep 24, 2026.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
45/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
c
Domain
security

Research direction

The bug is in cups/sidechannel.c lines 322-331 in cupsSideChannelSNMPGet() and a similar function cupsSideChannelSNMPWalk(). Start by reading the sidechannel.c file to understand the buffer handling and the _cupsBufferGet() function. The fix involves checking that the null terminator is within real_datalen before using strlen, and correcting the size check in SNMPWalk. Test by building CUPS and running any sidechannel-related tests.

Written by the indexing model from the issue text.

Description

investigating

Problem:
cupsSideChannelSNMPGet() takes the OID length from strlen(real_data) + 1 without checking that the nul terminator is inside the real_datalen bytes the backend actually sent, so strlen() runs into the uninitialised tail of the _cupsBufferGet() buffer. real_datalen then goes negative, the "(real_datalen + 1) > *datalen" check passes for any caller buffer, and memcpy() gets (size_t)real_datalen as its size.
https://github.com/OpenPrinting/cups/blob/e72b70245fbe81242a959be0ed1cbfc9dbefcd9a/cups/sidechannel.c#L322-L331

cupsSideChannelSNMPWalk() has the same flaw and its guard against it, "if ((size_t)real_datalen < sizeof(real_data))", measures a char pointer instead of the 65540 byte buffer, so it only fires when real_datalen is below 8.

Found by Linux Verification Center (portal.linuxtesting.ru) with SVACE.
Reporter: Pavel Nekrasov ([email protected]).

Dominant language
C
Stars
1.8k
Forks
331
Avg merge
15h 28m
Merged PRs (30d)
5

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from OpenPrinting/cups

All issues in OpenPrinting/cups

Similar issues

More C issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.