From: Tristan Madani <[email protected]>
ovsdb_jsonrpc_monitor_create() validates the params array length for
monitor_cond (V2, expects 3) and monitor_cond_since (V3, expects 4),
but not for monitor (V1).
A monitor request with fewer than 3 elements causes json_array_at()
to return NULL for indices 1 and 2. The subsequent dereference of
monitor_requests->type crashes ovsdb-server.
Add V1 to the existing bounds check so it requires exactly 3 params,
matching the V2 check. Before commit 9167cb52fa87 ("ovsdb-monitor:
Support monitor_cond_since."), the original guard checked all versions
uniformly; that commit narrowed the check to V2/V3 only.
Fixes: 9167cb52fa87 ("ovsdb-monitor: Support monitor_cond_since.")
Signed-off-by: Tristan Madani <[email protected]>
---
ovsdb/jsonrpc-server.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/ovsdb/jsonrpc-server.c b/ovsdb/jsonrpc-server.c
index 175f7bb4..92beb8ab 100644
--- a/ovsdb/jsonrpc-server.c
+++ b/ovsdb/jsonrpc-server.c
@@ -1503,7 +1503,8 @@ ovsdb_jsonrpc_monitor_create(struct ovsdb_jsonrpc_session
*s, struct ovsdb *db,
struct shash_node *node;
struct json *json;
- if ((version == OVSDB_MONITOR_V2 && json_array_size(params) != 3) ||
+ if (((version == OVSDB_MONITOR_V1 || version == OVSDB_MONITOR_V2)
+ && json_array_size(params) != 3) ||
(version == OVSDB_MONITOR_V3 && json_array_size(params) != 4)) {
error = ovsdb_syntax_error(params, NULL, "invalid parameters");
goto error;
--
2.53.0
_______________________________________________
dev mailing list
[email protected]
https://mail.openvswitch.org/mailman/listinfo/ovs-dev