Skip to content
体验新版
项目
组织
正在加载...
登录
切换导航
打开侧边栏
k3s
rt-thread
提交
69e5b10e
R
rt-thread
项目概览
k3s
/
rt-thread
与 Fork 源项目一致
Fork自
RT-Thread / rt-thread
通知
1
Star
0
Fork
0
代码
文件
提交
分支
Tags
贡献者
分支图
Diff
Issue
0
列表
看板
标记
里程碑
合并请求
0
DevOps
流水线
流水线任务
计划
Wiki
0
Wiki
分析
仓库
DevOps
项目成员
Pages
R
rt-thread
项目概览
项目概览
详情
发布
仓库
仓库
文件
提交
分支
标签
贡献者
分支图
比较
Issue
0
Issue
0
列表
看板
标记
里程碑
合并请求
0
合并请求
0
Pages
DevOps
DevOps
流水线
流水线任务
计划
分析
分析
仓库分析
DevOps
Wiki
0
Wiki
成员
成员
收起侧边栏
关闭侧边栏
动态
分支图
创建新Issue
流水线任务
提交
Issue看板
体验新版 GitCode,发现更多精彩内容 >>
未验证
提交
69e5b10e
编写于
4月 03, 2023
作者:
H
HUST_lxq
提交者:
GitHub
4月 03, 2023
浏览文件
操作
浏览文件
下载
电子邮件补丁
差异文件
[at_socket.c] Fix null pointer vulnerability caused by the variable at_sock (#7166)
上级
e49140b5
变更
1
显示空白变更内容
内联
并排
Showing
1 changed file
with
11 addition
and
9 deletion
+11
-9
components/net/at/at_socket/at_socket.c
components/net/at/at_socket/at_socket.c
+11
-9
未找到文件。
components/net/at/at_socket/at_socket.c
浏览文件 @
69e5b10e
...
@@ -70,9 +70,9 @@ struct at_socket *at_get_socket(int socket)
...
@@ -70,9 +70,9 @@ struct at_socket *at_get_socket(int socket)
rt_slist_for_each
(
node
,
&
_socket_list
)
rt_slist_for_each
(
node
,
&
_socket_list
)
{
{
at_sock
=
rt_slist_entry
(
node
,
struct
at_socket
,
list
);
at_sock
=
rt_slist_entry
(
node
,
struct
at_socket
,
list
);
if
(
socket
==
at_sock
->
socket
)
if
(
at_sock
&&
socket
==
at_sock
->
socket
)
{
{
if
(
at_sock
&&
at_sock
->
magic
==
AT_SOCKET_MAGIC
)
if
(
at_sock
->
magic
==
AT_SOCKET_MAGIC
)
{
{
rt_hw_interrupt_enable
(
level
);
rt_hw_interrupt_enable
(
level
);
return
at_sock
;
return
at_sock
;
...
@@ -97,9 +97,9 @@ struct at_socket *at_get_base_socket(int base_socket)
...
@@ -97,9 +97,9 @@ struct at_socket *at_get_base_socket(int base_socket)
rt_slist_for_each
(
node
,
&
_socket_list
)
rt_slist_for_each
(
node
,
&
_socket_list
)
{
{
at_sock
=
rt_slist_entry
(
node
,
struct
at_socket
,
list
);
at_sock
=
rt_slist_entry
(
node
,
struct
at_socket
,
list
);
if
(
base_socket
==
(
int
)
at_sock
->
user_data
&&
at_sock
->
state
!=
AT_SOCKET_LISTEN
)
if
(
at_sock
&&
base_socket
==
(
int
)
at_sock
->
user_data
&&
at_sock
->
state
!=
AT_SOCKET_LISTEN
)
{
{
if
(
at_sock
&&
at_sock
->
magic
==
AT_SOCKET_MAGIC
)
if
(
at_sock
->
magic
==
AT_SOCKET_MAGIC
)
{
{
rt_hw_interrupt_enable
(
level
);
rt_hw_interrupt_enable
(
level
);
return
at_sock
;
return
at_sock
;
...
@@ -149,7 +149,7 @@ static int at_recvpkt_all_delete(rt_slist_t *rlist)
...
@@ -149,7 +149,7 @@ static int at_recvpkt_all_delete(rt_slist_t *rlist)
{
{
pkt
=
rt_slist_entry
(
node
,
struct
at_recv_pkt
,
list
);
pkt
=
rt_slist_entry
(
node
,
struct
at_recv_pkt
,
list
);
node
=
rt_slist_next
(
node
);
node
=
rt_slist_next
(
node
);
if
(
pkt
->
buff
)
if
(
pkt
&&
pkt
->
buff
)
{
{
rt_free
(
pkt
->
buff
);
rt_free
(
pkt
->
buff
);
}
}
...
@@ -176,7 +176,7 @@ static int at_recvpkt_node_delete(rt_slist_t *rlist, rt_slist_t *node)
...
@@ -176,7 +176,7 @@ static int at_recvpkt_node_delete(rt_slist_t *rlist, rt_slist_t *node)
rt_slist_remove
(
rlist
,
node
);
rt_slist_remove
(
rlist
,
node
);
pkt
=
rt_slist_entry
(
node
,
struct
at_recv_pkt
,
list
);
pkt
=
rt_slist_entry
(
node
,
struct
at_recv_pkt
,
list
);
if
(
pkt
->
buff
)
if
(
pkt
&&
pkt
->
buff
)
{
{
rt_free
(
pkt
->
buff
);
rt_free
(
pkt
->
buff
);
}
}
...
@@ -209,6 +209,8 @@ static size_t at_recvpkt_get(rt_slist_t *rlist, char *mem, size_t len)
...
@@ -209,6 +209,8 @@ static size_t at_recvpkt_get(rt_slist_t *rlist, char *mem, size_t len)
free_node
=
node
;
free_node
=
node
;
node
=
rt_slist_next
(
node
);
node
=
rt_slist_next
(
node
);
if
(
!
pkt
)
continue
;
page_pos
=
pkt
->
bfsz_totle
-
pkt
->
bfsz_index
;
page_pos
=
pkt
->
bfsz_totle
-
pkt
->
bfsz_index
;
if
(
page_pos
>=
len
-
content_pos
)
if
(
page_pos
>=
len
-
content_pos
)
...
@@ -330,7 +332,7 @@ static int alloc_empty_socket(rt_slist_t *l)
...
@@ -330,7 +332,7 @@ static int alloc_empty_socket(rt_slist_t *l)
rt_slist_for_each
(
node
,
&
_socket_list
)
rt_slist_for_each
(
node
,
&
_socket_list
)
{
{
at_sock
=
rt_slist_entry
(
node
,
struct
at_socket
,
list
);
at_sock
=
rt_slist_entry
(
node
,
struct
at_socket
,
list
);
if
(
at_sock
->
socket
!=
idx
)
if
(
at_sock
&&
at_sock
->
socket
!=
idx
)
break
;
break
;
idx
++
;
idx
++
;
pre_node
=
node
;
pre_node
=
node
;
...
@@ -527,9 +529,9 @@ static int free_socket(struct at_socket *sock)
...
@@ -527,9 +529,9 @@ static int free_socket(struct at_socket *sock)
rt_slist_for_each
(
node
,
&
_socket_list
)
rt_slist_for_each
(
node
,
&
_socket_list
)
{
{
at_sock
=
rt_slist_entry
(
node
,
struct
at_socket
,
list
);
at_sock
=
rt_slist_entry
(
node
,
struct
at_socket
,
list
);
if
(
sock
->
socket
==
at_sock
->
socket
)
if
(
at_sock
&&
sock
->
socket
==
at_sock
->
socket
)
{
{
if
(
at_sock
&&
at_sock
->
magic
==
AT_SOCKET_MAGIC
)
if
(
at_sock
->
magic
==
AT_SOCKET_MAGIC
)
{
{
rt_slist_remove
(
&
_socket_list
,
&
at_sock
->
list
);
rt_slist_remove
(
&
_socket_list
,
&
at_sock
->
list
);
break
;
break
;
...
...
编辑
预览
Markdown
is supported
0%
请重试
或
添加新附件
.
添加附件
取消
You are about to add
0
people
to the discussion. Proceed with caution.
先完成此消息的编辑!
取消
想要评论请
注册
或
登录