From: Timo Sirainen Date: Sun, 3 May 2026 16:20:00 +0000 (+0000) Subject: [PATCH 1/2] login-common: Fix crash when XCLIENT FORWARD= base64 contains NUL byte X-Git-Tag: archive/raspbian/1%2.4.1+dfsg1-6+rpi1+deb13u7^2~2 X-Git-Url: https://dgit.raspbian.org/?a=commitdiff_plain;h=5e83291d6e3f6a2a8b7942fddcfe36ab1f1a9878;p=dovecot.git [PATCH 1/2] login-common: Fix crash when XCLIENT FORWARD= base64 contains NUL byte Sending "XCLIENT FORWARD=AA==" (base64 for a single NUL byte) followed by a regular login crashed pop3-login (and other login services) with: Panic: file ../../src/lib/array.h: line 275 (array_idx_i): assertion failed: (idx < array->buffer->used / array->element_size) p_strsplit_tabescaped() truncates at the first NUL, so an all-NUL payload produced an empty fields list. forward_fields was still created (but empty), and the later array_front() call in sasl_server_auth_begin() then panicked on the empty array. Reject empty payloads and payloads containing NUL bytes during base64 decode, so the array is never created in this case. Gbp-Pq: Name 0001-login-common-Fix-crash-when-XCLIENT-FORWARD-base64-c.patch --- diff --git a/src/login-common/client-common.c b/src/login-common/client-common.c index eeb9d6d..00e4f9a 100644 --- a/src/login-common/client-common.c +++ b/src/login-common/client-common.c @@ -988,6 +988,11 @@ bool client_forward_decode_base64(struct client *client, const char *value) string_t *str = t_str_new(MAX_BASE64_DECODED_SIZE(value_len)); if (base64_decode(value, value_len, str) < 0) return FALSE; + /* Embedded NUL would yield a created-but-empty array, panicking later + in array_front() during sasl_server_auth_begin(). */ + if (str_len(str) == 0 || + memchr(str_data(str), '\0', str_len(str)) != NULL) + return FALSE; char **_fields = p_strsplit_tabescaped(client->preproxy_pool, str_c(str));