diff mbox series

[2/4] stkutil: Fix CVE-2024-7543

Message ID 20241203194352.25514-2-ivo.g.dimitrov.75@gmail.com (mailing list archive)
State Accepted
Commit 90e60ada012de42964214d8155260f5749d0dcc7
Headers show
Series [1/4] stkutil: Fix CVE-2024-7544 | expand

Commit Message

Ivaylo Dimitrov Dec. 3, 2024, 7:43 p.m. UTC
---
 src/stkutil.c | 4 ++++
 1 file changed, 4 insertions(+)
diff mbox series

Patch

diff --git a/src/stkutil.c b/src/stkutil.c
index 066731c9..b6d4b537 100644
--- a/src/stkutil.c
+++ b/src/stkutil.c
@@ -1862,6 +1862,10 @@  static bool parse_dataobj_mms_reference(struct comprehension_tlv_iter *iter,
 
 	data = comprehension_tlv_iter_get_data(iter);
 	mr->len = len;
+
+	if (len > sizeof(mr->ref))
+		return false;
+
 	memcpy(mr->ref, data, len);
 
 	return true;