]> dgit.raspbian.org Git - dovecot.git/commitdiff
[PATCH 1/2] imap-hibernate: Fix out-of-bounds read when parsing DONE command tag
authorTimo Sirainen <timo.sirainen@open-xchange.com>
Thu, 16 Apr 2026 21:12:13 +0000 (23:12 +0200)
committerNoah Meyerhans <noahm@debian.org>
Wed, 16 Sep 2026 19:06:35 +0000 (15:06 -0400)
The tag-skipping loop was missing a size>0 guard, so a malformed
DONE command with no space/CR/tab terminator after the tag would
read one byte past the end of the buffer. Also add a \0 check to
stop on embedded null bytes, which are not valid tag characters.

Gbp-Pq: Name 0001-imap-hibernate-Fix-out-of-bounds-read-when-parsing-D.patch

src/imap-hibernate/imap-client.c

index 5c11dd1ddedf1fa20633f8d9d49b86d7a88a68c2..2110fe8e8e5f943902b414c77167d4524a794da3 100644 (file)
@@ -362,9 +362,11 @@ imap_client_input_parse(const unsigned char *data, size_t size, const char **tag
        tag_start = data;
 
        /* skip over tag */
-       while(data[0] != ' ' &&
+       while(size > 0 &&
+             data[0] != ' ' &&
              data[0] != '\r' &&
-             data[0] != '\t' ) { data++; size--; }
+             data[0] != '\t' &&
+             data[0] != '\0') { data++; size--; }
 
        tag_end = data;