git: 04fcf3096126 - main - dummynet: do not overflow the points[ED_MAX_SAMPLES_NO] array
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Tue, 22 Sep 2026 02:37:12 UTC
The branch main has been updated by maxim:
URL: https://cgit.FreeBSD.org/src/commit/?id=04fcf30961266cd77139b40774cb0d6ef6eb2be5
commit 04fcf30961266cd77139b40774cb0d6ef6eb2be5
Author: Maxim Konovalov <maxim@FreeBSD.org>
AuthorDate: 2026-09-21 23:32:09 +0000
Commit: Maxim Konovalov <maxim@FreeBSD.org>
CommitDate: 2026-09-22 02:36:46 +0000
dummynet: do not overflow the points[ED_MAX_SAMPLES_NO] array
Otherwise, the following would segfault
dnctl pipe 1 config bw 1Mbit/s profile 1025points.txt
Found with: Claude Code Sonnet 5
MFC after: 2 weeks
---
sbin/ipfw/dummynet.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/sbin/ipfw/dummynet.c b/sbin/ipfw/dummynet.c
index a0cefcffd183..3cf9a1854365 100644
--- a/sbin/ipfw/dummynet.c
+++ b/sbin/ipfw/dummynet.c
@@ -959,6 +959,9 @@ load_extra_delays(const char *filename, struct dn_profile *p,
} else if (do_points) {
if (!is_valid_number(name) || !is_valid_number(arg))
errx(ED_EFMT("invalid point found"));
+ if (points_no >= ED_MAX_SAMPLES_NO)
+ errx(ED_EFMT("too many samples, maximum is %d"),
+ ED_MAX_SAMPLES_NO);
if (delay_first) {
points[points_no].delay = atof(name);
points[points_no].prob = atof(arg);