Skip to content

Commit 0ca6ead

Browse files
kevinbackhousettaylorr
authored andcommitted
alias.c: reject too-long cmdline strings in split_cmdline()
This function improperly uses an int to represent the number of entries in the resulting argument array. This allows a malicious actor to intentionally overflow the return value, leading to arbitrary heap writes. Because the resulting argv array is typically passed to execv(), it may be possible to leverage this attack to gain remote code execution on a victim machine. This was almost certainly the case for certain configurations of git-shell until the previous commit limited the size of input it would accept. Other calls to split_cmdline() are typically limited by the size of argv the OS is willing to hand us, so are similarly protected. So this is not strictly fixing a known vulnerability, but is a hardening of the function that is worth doing to protect against possible unknown vulnerabilities. One approach to fixing this would be modifying the signature of `split_cmdline()` to look something like: int split_cmdline(char *cmdline, const char ***argv, size_t *argc); Where the return value of `split_cmdline()` is negative for errors, and zero otherwise. If non-NULL, the `*argc` pointer is modified to contain the size of the `**argv` array. But this implies an absurdly large `argv` array, which more than likely larger than the system's argument limit. So even if split_cmdline() allowed this, it would fail immediately afterwards when we called execv(). So instead of converting all of `split_cmdline()`'s callers to work with `size_t` types in this patch, instead pursue the minimal fix here to prevent ever returning an array with more than INT_MAX entries in it. Signed-off-by: Kevin Backhouse <[email protected]> Signed-off-by: Taylor Blau <[email protected]> Signed-off-by: Jeff King <[email protected]> Signed-off-by: Taylor Blau <[email protected]>
1 parent 71ad7fe commit 0ca6ead

File tree

1 file changed

+9
-2
lines changed

1 file changed

+9
-2
lines changed

alias.c

Lines changed: 9 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -46,14 +46,16 @@ void list_aliases(struct string_list *list)
4646

4747
#define SPLIT_CMDLINE_BAD_ENDING 1
4848
#define SPLIT_CMDLINE_UNCLOSED_QUOTE 2
49+
#define SPLIT_CMDLINE_ARGC_OVERFLOW 3
4950
static const char *split_cmdline_errors[] = {
5051
N_("cmdline ends with \\"),
51-
N_("unclosed quote")
52+
N_("unclosed quote"),
53+
N_("too many arguments"),
5254
};
5355

5456
int split_cmdline(char *cmdline, const char ***argv)
5557
{
56-
int src, dst, count = 0, size = 16;
58+
size_t src, dst, count = 0, size = 16;
5759
char quoted = 0;
5860

5961
ALLOC_ARRAY(*argv, size);
@@ -96,6 +98,11 @@ int split_cmdline(char *cmdline, const char ***argv)
9698
return -SPLIT_CMDLINE_UNCLOSED_QUOTE;
9799
}
98100

101+
if (count >= INT_MAX) {
102+
FREE_AND_NULL(*argv);
103+
return -SPLIT_CMDLINE_ARGC_OVERFLOW;
104+
}
105+
99106
ALLOC_GROW(*argv, count + 1, size);
100107
(*argv)[count] = NULL;
101108

0 commit comments

Comments
 (0)