From f15ed311c0299e19fd3bf208671d506a4dc002a9 Mon Sep 17 00:00:00 2001 From: lipengfei28 Date: Wed, 25 Sep 2024 18:13:53 +0800 Subject: [PATCH] wapi_json_load: the buf need add null character sched_backtrace+0xd4/0xfffffffffff444e0 sched_dumpstack+0x5c/0xc50a0 _assert+0x1a0/0x11cf380 __assert+0x28/0x4ebd70 kasan_report+0x280/0x5b0 __asan_loadN+0x234/0xfffffffffffffac0 strlen+0x3c/0x838410 cJSON_Parse+0x38/0x1d0 wapi_json_load+0xc4/0x1c0 wapi_load_config+0x50/0x110600 netinit_associate+0x34/0xfffffffffffffe70 netinit_thread+0xbc/0x18ad0 pthread_startup+0x34/0x11660a0 pthread_start+0x84/0xfffffffffeea2520 If the buf no null character, the strlen acces buf maybe out of bounds Signed-off-by: lipengfei28 --- wireless/wapi/src/util.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/wireless/wapi/src/util.c b/wireless/wapi/src/util.c index 9104d28e9..e22b8c18e 100644 --- a/wireless/wapi/src/util.c +++ b/wireless/wapi/src/util.c @@ -89,12 +89,13 @@ static FAR void *wapi_json_load(FAR const char *confname) return NULL; } - buf = malloc(sb.st_size); + buf = malloc(sb.st_size + 1); if (!buf) { goto errout; } + buf[sb.st_size] = '\0'; fd = open(confname, O_RDONLY); if (fd < 0) {