]> dgit.raspbian.org Git - dovecot.git/commitdiff
[PATCH 1/2] login-common: Fix crash when XCLIENT FORWARD= base64 contains NUL byte
authorTimo Sirainen <timo.sirainen@open-xchange.com>
Sun, 3 May 2026 16:20:00 +0000 (16:20 +0000)
committerNoah Meyerhans <noahm@debian.org>
Wed, 16 Sep 2026 19:06:35 +0000 (15:06 -0400)
Sending "XCLIENT FORWARD=AA==" (base64 for a single NUL byte) followed
by a regular login crashed pop3-login (and other login services) with:

  Panic: file ../../src/lib/array.h: line 275 (array_idx_i):
  assertion failed: (idx < array->buffer->used / array->element_size)

p_strsplit_tabescaped() truncates at the first NUL, so an all-NUL
payload produced an empty fields list. forward_fields was still
created (but empty), and the later array_front() call in
sasl_server_auth_begin() then panicked on the empty array.

Reject empty payloads and payloads containing NUL bytes during base64
decode, so the array is never created in this case.

Gbp-Pq: Name 0001-login-common-Fix-crash-when-XCLIENT-FORWARD-base64-c.patch

src/login-common/client-common.c

index eeb9d6da053dbf9f230ea6d37337da350fa2b041..00e4f9abbf9f88fdf2835e27722f9b234572b10d 100644 (file)
@@ -988,6 +988,11 @@ bool client_forward_decode_base64(struct client *client, const char *value)
        string_t *str = t_str_new(MAX_BASE64_DECODED_SIZE(value_len));
        if (base64_decode(value, value_len, str) < 0)
                return FALSE;
+       /* Embedded NUL would yield a created-but-empty array, panicking later
+          in array_front() during sasl_server_auth_begin(). */
+       if (str_len(str) == 0 ||
+           memchr(str_data(str), '\0', str_len(str)) != NULL)
+               return FALSE;
 
        char **_fields = p_strsplit_tabescaped(client->preproxy_pool,
                                               str_c(str));