This is an automated email from the ASF dual-hosted git repository. xiaoxiang781216 pushed a commit to branch master in repository https://gitbox.apache.org/repos/asf/nuttx.git
commit b8f4213b6027a61a862208e6a05763ac2f86bb5a Author: yushuailong <[email protected]> AuthorDate: Wed Sep 16 15:52:49 2026 +0800 sched/module: Fix a line buffer overread in /proc/modules. modprocfs_callback() formatted each line into line[64] with snprintf() and passed snprintf()'s return value, the length the line would have had, to procfs_memcpy() as the source length. A module name longer than a few characters therefore made the copy read past the end of the line buffer and hand kernel heap memory to the reader, and grew totalsize by the difference. Use procfs_snprintf(), which returns the length actually written, as the other procfs entries already do. Assisted-by: OpenAI Codex Signed-off-by: yushuailong <[email protected]> --- sched/module/mod_procfs.c | 19 +++++++++---------- 1 file changed, 9 insertions(+), 10 deletions(-) diff --git a/sched/module/mod_procfs.c b/sched/module/mod_procfs.c index 60491c1975d..230c6f89b25 100644 --- a/sched/module/mod_procfs.c +++ b/sched/module/mod_procfs.c @@ -28,7 +28,6 @@ #include <sys/stat.h> -#include <stdio.h> #include <stdint.h> #include <stdbool.h> #include <string.h> @@ -136,15 +135,15 @@ static int modprocfs_callback(FAR struct module_s *modp, FAR void *arg) DEBUGASSERT(modp != NULL && arg != NULL); priv = (FAR struct modprocfs_file_s *)arg; - linesize = snprintf(priv->line, MOD_LINELEN, - "%s,%p,%p,%u,%p,%lu,%p,%lu\n", - modp->modname, - modp->modinfo.uninitializer, modp->modinfo.arg, - modp->modinfo.nexports, - modp->textalloc, - (unsigned long)modp->textsize, - (FAR uint8_t *)modp->dataalloc, - (unsigned long)modp->datasize); + linesize = procfs_snprintf(priv->line, MOD_LINELEN, + "%s,%p,%p,%u,%p,%lu,%p,%lu\n", + modp->modname, + modp->modinfo.uninitializer, modp->modinfo.arg, + modp->modinfo.nexports, + modp->textalloc, + (unsigned long)modp->textsize, + (FAR uint8_t *)modp->dataalloc, + (unsigned long)modp->datasize); copysize = procfs_memcpy(priv->line, linesize, priv->buffer, priv->remaining, &priv->offset); priv->totalsize += copysize;
