From: Tristan Madani <[email protected]>

ovsdb_jsonrpc_monitor_create() validates the params array length for
monitor_cond (V2, expects 3) and monitor_cond_since (V3, expects 4),
but not for monitor (V1).

A monitor request with fewer than 3 elements causes json_array_at()
to return NULL for indices 1 and 2.  The subsequent dereference of
monitor_requests->type crashes ovsdb-server.

Add V1 to the existing bounds check so it requires exactly 3 params,
matching the V2 check.  Before commit 9167cb52fa87 ("ovsdb-monitor:
Support monitor_cond_since."), the original guard checked all versions
uniformly; that commit narrowed the check to V2/V3 only.

Fixes: 9167cb52fa87 ("ovsdb-monitor: Support monitor_cond_since.")
Signed-off-by: Tristan Madani <[email protected]>
---
 ovsdb/jsonrpc-server.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/ovsdb/jsonrpc-server.c b/ovsdb/jsonrpc-server.c
index 175f7bb4..92beb8ab 100644
--- a/ovsdb/jsonrpc-server.c
+++ b/ovsdb/jsonrpc-server.c
@@ -1503,7 +1503,8 @@ ovsdb_jsonrpc_monitor_create(struct ovsdb_jsonrpc_session 
*s, struct ovsdb *db,
     struct shash_node *node;
     struct json *json;
 
-    if ((version == OVSDB_MONITOR_V2 && json_array_size(params) != 3) ||
+    if (((version == OVSDB_MONITOR_V1 || version == OVSDB_MONITOR_V2)
+         && json_array_size(params) != 3) ||
         (version == OVSDB_MONITOR_V3 && json_array_size(params) != 4)) {
         error = ovsdb_syntax_error(params, NULL, "invalid parameters");
         goto error;
-- 
2.53.0

_______________________________________________
dev mailing list
[email protected]
https://mail.openvswitch.org/mailman/listinfo/ovs-dev

Reply via email to