Path: blob/main/website/static/security/patches/EN-09:01/kenv.patch
18096 views
Index: sys/kern/kern_environment.c1===================================================================2--- sys/kern/kern_environment.c (revision 190221)3+++ sys/kern/kern_environment.c (working copy)4@@ -87,7 +87,7 @@5} */ *uap;6{7char *name, *value, *buffer = NULL;8- size_t len, done, needed;9+ size_t len, done, needed, buflen;10int error, i;1112KASSERT(dynamic_kenv, ("kenv: dynamic_kenv = 0"));13@@ -100,13 +100,17 @@14return (error);15#endif16done = needed = 0;17+ buflen = uap->len;18+ if (buflen > KENV_SIZE * (KENV_MNAMELEN + KENV_MVALLEN + 2))19+ buflen = KENV_SIZE * (KENV_MNAMELEN +20+ KENV_MVALLEN + 2);21if (uap->len > 0 && uap->value != NULL)22- buffer = malloc(uap->len, M_TEMP, M_WAITOK|M_ZERO);23+ buffer = malloc(buflen, M_TEMP, M_WAITOK|M_ZERO);24mtx_lock(&kenv_lock);25for (i = 0; kenvp[i] != NULL; i++) {26len = strlen(kenvp[i]) + 1;27needed += len;28- len = min(len, uap->len - done);29+ len = min(len, buflen - done);30/*31* If called with a NULL or insufficiently large32* buffer, just keep computing the required size.333435