Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Buffer overflow in cupsSideChannelSNMPGet()

Aperta
#1,719 0 commenti 0 reazioni 1 assegnatario Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

@michaelrsweet ci sta già lavorando.

Dal 24/9/2026.

Valutazione

Difficoltà
4/5
Tempo stimato
3-5 giorni
Idoneità per principianti
45/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
c
Ambito
security

Direzione di ricerca

The bug is in cups/sidechannel.c lines 322-331 in cupsSideChannelSNMPGet() and a similar function cupsSideChannelSNMPWalk(). Start by reading the sidechannel.c file to understand the buffer handling and the _cupsBufferGet() function. The fix involves checking that the null terminator is within real_datalen before using strlen, and correcting the size check in SNMPWalk. Test by building CUPS and running any sidechannel-related tests.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

investigating

Problem:
cupsSideChannelSNMPGet() takes the OID length from strlen(real_data) + 1 without checking that the nul terminator is inside the real_datalen bytes the backend actually sent, so strlen() runs into the uninitialised tail of the _cupsBufferGet() buffer. real_datalen then goes negative, the "(real_datalen + 1) > *datalen" check passes for any caller buffer, and memcpy() gets (size_t)real_datalen as its size.
https://github.com/OpenPrinting/cups/blob/e72b70245fbe81242a959be0ed1cbfc9dbefcd9a/cups/sidechannel.c#L322-L331

cupsSideChannelSNMPWalk() has the same flaw and its guard against it, "if ((size_t)real_datalen < sizeof(real_data))", measures a char pointer instead of the 65540 byte buffer, so it only fires when real_datalen is below 8.

Found by Linux Verification Center (portal.linuxtesting.ru) with SVACE.
Reporter: Pavel Nekrasov ([email protected]).

Lingua principale
C
Stelle
1.8k
Fork
331
Merge medio
15h 28m
PR unite (30g)
5

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di OpenPrinting/cups

Tutte le issue di OpenPrinting/cups

Issue simili

Altre issue su C

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.