This is an automated email from the ASF dual-hosted git repository.

xiaoxiang781216 pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/nuttx.git

commit b8f4213b6027a61a862208e6a05763ac2f86bb5a
Author: yushuailong <[email protected]>
AuthorDate: Wed Sep 16 15:52:49 2026 +0800

    sched/module: Fix a line buffer overread in /proc/modules.
    
    modprocfs_callback() formatted each line into line[64] with snprintf()
    and passed snprintf()'s return value, the length the line would have
    had, to procfs_memcpy() as the source length.  A module name longer
    than a few characters therefore made the copy read past the end of
    the line buffer and hand kernel heap memory to the reader, and grew
    totalsize by the difference.
    
    Use procfs_snprintf(), which returns the length actually written, as
    the other procfs entries already do.
    
    Assisted-by: OpenAI Codex
    Signed-off-by: yushuailong <[email protected]>
---
 sched/module/mod_procfs.c | 19 +++++++++----------
 1 file changed, 9 insertions(+), 10 deletions(-)

diff --git a/sched/module/mod_procfs.c b/sched/module/mod_procfs.c
index 60491c1975d..230c6f89b25 100644
--- a/sched/module/mod_procfs.c
+++ b/sched/module/mod_procfs.c
@@ -28,7 +28,6 @@
 
 #include <sys/stat.h>
 
-#include <stdio.h>
 #include <stdint.h>
 #include <stdbool.h>
 #include <string.h>
@@ -136,15 +135,15 @@ static int modprocfs_callback(FAR struct module_s *modp, 
FAR void *arg)
   DEBUGASSERT(modp != NULL && arg != NULL);
   priv = (FAR struct modprocfs_file_s *)arg;
 
-  linesize = snprintf(priv->line, MOD_LINELEN,
-                      "%s,%p,%p,%u,%p,%lu,%p,%lu\n",
-                      modp->modname,
-                      modp->modinfo.uninitializer, modp->modinfo.arg,
-                      modp->modinfo.nexports,
-                      modp->textalloc,
-                      (unsigned long)modp->textsize,
-                      (FAR uint8_t *)modp->dataalloc,
-                      (unsigned long)modp->datasize);
+  linesize = procfs_snprintf(priv->line, MOD_LINELEN,
+                             "%s,%p,%p,%u,%p,%lu,%p,%lu\n",
+                             modp->modname,
+                             modp->modinfo.uninitializer, modp->modinfo.arg,
+                             modp->modinfo.nexports,
+                             modp->textalloc,
+                             (unsigned long)modp->textsize,
+                             (FAR uint8_t *)modp->dataalloc,
+                             (unsigned long)modp->datasize);
   copysize = procfs_memcpy(priv->line, linesize, priv->buffer,
                            priv->remaining, &priv->offset);
   priv->totalsize += copysize;

Reply via email to