royzah opened a new pull request, #20409: URL: https://github.com/apache/nuttx/pull/20409
## Why `binfmt_copyargv()` and `binfmt_copyactions()` size the kernel buffer in one pass over user memory and fill it in a second. A second thread that lengthens a string, or the list, between the two overflows the kernel heap. ## How One bounded fill: every string is cut at the space the first pass reserved, the list is walked at most as far as it was counted, and at most 256 actions. An unknown action is refused. ## Tested i.MX93, kernel build. One thread spawns a program 2000 times, each through the argv and file-action copies; another, pinned to the other core, flips the length of a 4 KB argument and of an open action's path between them: | | result | | --- | --- | | after | 1431077 flips, 2000 copies, kernel intact | | before | not won on hardware in 2000 tries; the overflow is in the two passes above | ``` 2000 spawns racing 1431077 flips of argv and file action lengths: kernel intact, 2000 reached the file action, 0 started ``` `tools/checkpatch.sh` clean. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
