From: Timo Sirainen Date: Thu, 16 Apr 2026 21:12:13 +0000 (+0200) Subject: [PATCH 1/2] imap-hibernate: Fix out-of-bounds read when parsing DONE command tag X-Git-Tag: archive/raspbian/1%2.4.1+dfsg1-6+rpi1+deb13u7^2~43 X-Git-Url: https://dgit.raspbian.org/?a=commitdiff_plain;h=031e149d4c748659fe3470fb747c1c5878b5a1fb;p=dovecot.git [PATCH 1/2] imap-hibernate: Fix out-of-bounds read when parsing DONE command tag The tag-skipping loop was missing a size>0 guard, so a malformed DONE command with no space/CR/tab terminator after the tag would read one byte past the end of the buffer. Also add a \0 check to stop on embedded null bytes, which are not valid tag characters. Gbp-Pq: Name 0001-imap-hibernate-Fix-out-of-bounds-read-when-parsing-D.patch --- diff --git a/src/imap-hibernate/imap-client.c b/src/imap-hibernate/imap-client.c index 5c11dd1..2110fe8 100644 --- a/src/imap-hibernate/imap-client.c +++ b/src/imap-hibernate/imap-client.c @@ -362,9 +362,11 @@ imap_client_input_parse(const unsigned char *data, size_t size, const char **tag tag_start = data; /* skip over tag */ - while(data[0] != ' ' && + while(size > 0 && + data[0] != ' ' && data[0] != '\r' && - data[0] != '\t' ) { data++; size--; } + data[0] != '\t' && + data[0] != '\0') { data++; size--; } tag_end = data;