From: Thadeu Lima de Souza Cascardo Date: Mon, 13 May 2019 19:58:01 +0000 (-0300) Subject: ask-password: prevent buffer overflow when reading from keyring X-Git-Tag: archive/raspbian/242-4+rpi1^2~25 X-Git-Url: https://dgit.raspbian.org/?a=commitdiff_plain;h=6c0ab2b13cde51ebc0849927dc0fc9c8c9a4fb8c;p=systemd.git ask-password: prevent buffer overflow when reading from keyring When we read from keyring, a temporary buffer is allocated in order to determine the size needed for the entire data. However, when zeroing that area, we use the data size returned by the read instead of the lesser size allocate for the buffer. That will cause memory corruption that causes systemd-cryptsetup to crash either when a single large password is used or when multiple passwords have already been pushed to the keyring. Signed-off-by: Thadeu Lima de Souza Cascardo (cherry picked from commit 59c55e73eaee345e1ee67c23eace8895ed499693) Gbp-Pq: Name ask-password-prevent-buffer-overflow-when-reading-from-ke.patch --- diff --git a/src/shared/ask-password-api.c b/src/shared/ask-password-api.c index ab0c3469..6c0a3699 100644 --- a/src/shared/ask-password-api.c +++ b/src/shared/ask-password-api.c @@ -80,7 +80,7 @@ static int retrieve_key(key_serial_t serial, char ***ret) { if (n < m) break; - explicit_bzero_safe(p, n); + explicit_bzero_safe(p, m); if (m > LONG_MAX / 2) /* overflow check */ return -ENOMEM;