The item string in a flex item JSON configuration is formatted into a
256 byte stack buffer with sprintf().  A longer string overflows it:

  *** buffer overflow detected ***: terminated

Use snprintf() and reject the item if it does not fit.

Fixes: 59f3a8acbcdb ("app/testpmd: add flex item commands")
Cc: [email protected]

Signed-off-by: Stephen Hemminger <[email protected]>
---
 app/test-pmd/cmd_flex_item.c | 11 +++++++----
 1 file changed, 7 insertions(+), 4 deletions(-)

diff --git a/app/test-pmd/cmd_flex_item.c b/app/test-pmd/cmd_flex_item.c
index c0bbff7b45..e62afe3cb5 100644
--- a/app/test-pmd/cmd_flex_item.c
+++ b/app/test-pmd/cmd_flex_item.c
@@ -135,10 +135,13 @@ flex_link_item_parse(const char *src, struct 
rte_flow_item *item)
        struct rte_flow_item *pattern;
        struct rte_flow_action *actions;
 
-       sprintf(flow_rule,
-               "flow create 0 pattern %s / end actions drop / end", src);
-       src = flow_rule;
-       ret = flow_parse(src, (void *)data, sizeof(data),
+       ret = snprintf(flow_rule, sizeof(flow_rule),
+                      "flow create 0 pattern %s / end actions drop / end", 
src);
+       if (ret < 0 || ret >= (int)sizeof(flow_rule)) {
+               printf("Flex item link \"%s\" is too long\n", src);
+               return -ENOSPC;
+       }
+       ret = flow_parse(flow_rule, (void *)data, sizeof(data),
                         &attr, &pattern, &actions);
        if (ret)
                return ret;
-- 
2.53.0

Reply via email to