Commit fc9c0c3
net: lib: nrf_cloud: mqtt: Fix integer underflow in topic prefix parsing
Fixed a signed integer underflow in nct_set_topic_prefix() where a
malformed topic prefix (e.g. "stage/" with no tenant segment) caused
len to compute as -1. Due to implicit signed-to-unsigned conversion,
the bounds check was bypassed and memcpy copied 63 bytes of memory
beyond the end of the input string into the tenant[] buffer.
Fixed by using size_t for all length variables and validating that
the topic prefix contains a non-empty tenant segment before computing
tenant_len.
Ref: SI-539
Signed-off-by: Noah Pendleton <noah.pendleton@nordicsemi.no>1 parent 7067226 commit fc9c0c3
1 file changed
Lines changed: 32 additions & 22 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
277 | 277 | | |
278 | 278 | | |
279 | 279 | | |
280 | | - | |
281 | | - | |
282 | | - | |
283 | | - | |
284 | | - | |
285 | | - | |
286 | | - | |
287 | | - | |
288 | | - | |
289 | | - | |
290 | | - | |
291 | | - | |
292 | | - | |
293 | | - | |
294 | | - | |
295 | | - | |
296 | | - | |
297 | | - | |
298 | | - | |
299 | | - | |
300 | | - | |
301 | | - | |
| 280 | + | |
| 281 | + | |
| 282 | + | |
| 283 | + | |
| 284 | + | |
| 285 | + | |
| 286 | + | |
| 287 | + | |
| 288 | + | |
| 289 | + | |
| 290 | + | |
| 291 | + | |
| 292 | + | |
| 293 | + | |
| 294 | + | |
| 295 | + | |
| 296 | + | |
| 297 | + | |
| 298 | + | |
| 299 | + | |
| 300 | + | |
| 301 | + | |
| 302 | + | |
| 303 | + | |
| 304 | + | |
| 305 | + | |
| 306 | + | |
| 307 | + | |
| 308 | + | |
| 309 | + | |
302 | 310 | | |
| 311 | + | |
| 312 | + | |
303 | 313 | | |
304 | 314 | | |
305 | 315 | | |
| |||
0 commit comments