Bug 15925 - Wrong size passed to memcpy in pdb_update_inode leads to missing xattrs when renaming
Summary: Wrong size passed to memcpy in pdb_update_inode leads to missing xattrs when ...
Status: RESOLVED FIXED
Alias: None
Product: Pseudo
Classification: Yocto Project Subprojects
Component: pseudo (show other bugs)
Version: master
Hardware: All Multiple
: Medium+ normal
Target Milestone: 5.3 M2
Assignee: Mark Hatle
QA Contact:
URL:
Whiteboard:
Depends on:
Blocks:
 
Reported: 2025-07-03 20:25 UTC by Daniele Romano
Modified: 2025-07-11 02:54 UTC (History)
4 users (show)

See Also:
OS type for building Yocto: ---
Type of Regression: ---
Verified:
Documentation change: No (bug/feature does not impact docs)


Attachments
Fix for oldmsg buffer allocation and memcpy data copied (710 bytes, patch)
2025-07-03 20:26 UTC, Daniele Romano
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Daniele Romano 2025-07-03 20:25:17 UTC
The pdb_update_inode function is unable to find a match and to correctly copy the xattr due to the wrong amount of data copied when cloning msg.


The issue is in the following code in pseudo_db.c:

2160 int pdb_update_inode(pseudo_msg_t *msg) {
.....
.....
2191	memcpy(oldmsg, msg, sizeof(msg) + msg->pathlen);
2192	found_existing = !pdb_find_file_path(oldmsg);
2193	if (found_existing) {
2194		/* we have an existing file entry */
2195		pdb_copy_xattrs(oldmsg, msg);
2196	}


The memcpy in line 2191 is copying "sizeof(msg) + msg->pathlen", but msg is a pointer to a pseudo_msg_t. This means that the amount of bytes copied is equal to msg->pathlen plus the size of a pointer and not the pseudo_msg_t itself. This issue will lead to a truncated path copied in oldmsg and to the failure of pdb_find_file_path function on line 2193.

The patch attached fixes line 2191 replacing "sizeof(msg)" with "sizeof(pseudo_msg_t)".

In addition, it fixes the allocation of the oldmsg buffer at line 2167. This is needed to avoid buffer overflows with paths very close to the maximum expected length that is given by the pseudo_path_max() function.
Comment 1 Daniele Romano 2025-07-03 20:26:16 UTC
Created attachment 5125 [details]
Fix for oldmsg buffer allocation and memcpy data copied
Comment 2 Mark Hatle 2025-07-11 02:52:52 UTC
The patch was tested, modified a bit and has been pushed.  See:

https://git.yoctoproject.org/pseudo/commit/?id=d1db9c219abf92f15303486a409292237f1fc790