Compare commits

..

9 Commits

Author SHA1 Message Date
Brian Witt 76b717be89
Merge cb2ca58e4b into 99ab67143a 2026-03-10 18:20:56 +08:00
Marc Kleine-Budde 99ab67143a
Merge pull request #625 from marckleinebudde/bcmserver-fix-buffer-overflow
bcmserver: fix buffer overflow
2026-03-10 10:58:56 +01:00
Marc Kleine-Budde a0aeaed234 bcmserver: main(): rxmsg: increase buffer size to hold long network interface names
Message-ID: <DM6PR17MB28748DA25E52E1BD3EC593E6937AA@DM6PR17MB2874.namprd17.prod.outlook.com>
2026-03-10 10:46:12 +01:00
Marc Kleine-Budde 3cae8a449b bcmserver: main(): convert from sprintf() to snprintf() to avoid buffer overflow
Message-ID: <DM6PR17MB28748DA25E52E1BD3EC593E6937AA@DM6PR17MB2874.namprd17.prod.outlook.com>
2026-03-10 10:46:11 +01:00
Marc Kleine-Budde 44e6eb45e3
Merge pull request #624 from marckleinebudde/canerrsim-fix-buffer-overflow
canerrsim: main(): avoid buffer overflow: check length of interface name
2026-03-09 12:27:28 +01:00
Marc Kleine-Budde 9e444073b1 canerrsim: main(): avoid buffer overflow: check length of interface name
Closes: https://github.com/linux-can/can-utils/issues/623
2026-03-09 12:23:29 +01:00
Marc Kleine-Budde 9d4f3c82a2 canerrsim: add missing \n at end of error messages 2026-03-09 12:21:33 +01:00
Marc Kleine-Budde 7e8e247b2f canerrsim: convert from show_custom_format_and_exit() to err_exit() 2026-03-09 12:20:50 +01:00
Marc Kleine-Budde 3fe1c42bbf canerrsim: err_exit(): add support for printf style formats 2026-03-09 12:18:10 +01:00
2 changed files with 47 additions and 28 deletions

View File

@ -153,7 +153,7 @@ int main(void)
char buf[MAXLEN];
char format[FORMATSZ];
char rxmsg[50];
char rxmsg[64];
#pragma GCC diagnostic push
#pragma GCC diagnostic ignored "-Wpragmas"
@ -234,7 +234,7 @@ int main(void)
}
while (1) {
again:
FD_ZERO(&readfds);
FD_SET(sc, &readfds);
FD_SET(sa, &readfds);
@ -242,6 +242,8 @@ int main(void)
select((sc > sa)?sc+1:sa+1, &readfds, NULL, NULL, NULL);
if (FD_ISSET(sc, &readfds)) {
size_t size = sizeof(rxmsg);
int len = 0, res;
recvfrom(sc, &msg, sizeof(msg), 0,
(struct sockaddr*)&caddr, &caddrlen);
@ -249,17 +251,35 @@ int main(void)
ifr.ifr_ifindex = caddr.can_ifindex;
ioctl(sc, SIOCGIFNAME, &ifr);
sprintf(rxmsg, "< %s %03X %d ", ifr.ifr_name,
res = snprintf(rxmsg, size, "< %s %03X %d ", ifr.ifr_name,
msg.msg_head.can_id, msg.frame.can_dlc);
if (res < 0 || (size_t)res >= size) {
printf("Error: rxmsg buffer (size %zu) too small for data.\n", size);
continue;
}
for ( i = 0; i < msg.frame.can_dlc; i++)
sprintf(rxmsg + strlen(rxmsg), "%02X ",
msg.frame.data[i]);
len += res;
for (i = 0; i < msg.frame.can_dlc; i++) {
res = snprintf(rxmsg + len, size - len, "%02X ", msg.frame.data[i]);
if (res < 0 || (size_t)res >= (size - len)) {
printf("Error: rxmsg buffer (size %zu) too small for data.\n", size);
goto again;
}
len += res;
}
/* delimiter '\0' for Adobe(TM) Flash(TM) XML sockets */
strcat(rxmsg, ">\0");
res = snprintf(rxmsg + len, size - len, ">");
if (res < 0 || (size_t)res >= (size - len)) {
printf("Error: rxmsg buffer (size %zu) too small for data.\n", size);
continue;
}
send(sa, rxmsg, strlen(rxmsg) + 1, 0);
len += res;
send(sa, rxmsg, len + 1, 0);
}

View File

@ -25,6 +25,7 @@
#include <linux/can/error.h>
#include <linux/can/raw.h>
#include <net/if.h>
#include <stdarg.h>
#include <stdbool.h>
#include <stdint.h>
#include <stdio.h>
@ -122,27 +123,25 @@ void show_help_and_exit()
exit(EXIT_SUCCESS);
}
void err_exit(const char *msg)
void __attribute__((format (printf, 1, 2))) err_exit(const char *format, ...)
{
printf("%s", msg);
exit(EXIT_FAILURE);
}
va_list ap;
void show_custom_format_and_exit(const char *param, const char *format)
{
char str_buf[80];
sprintf(str_buf, format, param);
err_exit(str_buf);
va_start(ap, format);
vfprintf(stdout, format, ap);
va_end(ap);
exit(EXIT_FAILURE);
}
void show_invalid_option(const char *option)
{
show_custom_format_and_exit(option, "Error: Invalid option %s\n");
err_exit("Error: Invalid option %s\n", option);
}
void show_err_and_exit(const char *err_type)
{
show_custom_format_and_exit(err_type, "Error: You can only have one %s parameter!\n");
err_exit("Error: You can only have one %s parameter!\n", err_type);
}
void show_loc_err_and_exit()
@ -176,7 +175,6 @@ int main(int argc, char *argv[])
struct ifreq ifr;
struct can_frame frame;
bool show_bits = false, location_processed = false, transceiver_processed = false, arbitration_processed = false;
char tmp_str[256];
printf("CAN Sockets Error Messages Simulator\n");
if (argc < 3)
@ -537,24 +535,25 @@ int main(int argc, char *argv[])
// create socket
if ((sock = socket(PF_CAN, SOCK_RAW, CAN_RAW)) < 0)
err_exit("Error while opening socket");
err_exit("Error while opening socket\n");
// set interface name
if (strlen(argv[1]) >= IFNAMSIZ)
err_exit("Name of CAN device '%s' is too long!\n\n", argv[1]);
strcpy(ifr.ifr_name, argv[1]); // can0, vcan0...
if (ioctl(sock, SIOCGIFINDEX, &ifr) < 0) {
sprintf(tmp_str, "Error setting CAN interface name %s", argv[1]);
err_exit(tmp_str);
}
if (ioctl(sock, SIOCGIFINDEX, &ifr) < 0)
err_exit("Error setting CAN interface name %s\n", argv[1]);
// bind socket to the CAN interface
addr.can_family = AF_CAN;
addr.can_ifindex = ifr.ifr_ifindex;
if (bind(sock, (struct sockaddr *)&addr, sizeof(addr)) < 0)
err_exit("Error in socket bind");
err_exit("Error in socket bind\n");
// Send CAN error frame
if (write(sock, &frame, sizeof(frame)) < 0)
err_exit("Error writing to socket");
err_exit("Error writing to socket\n");
else
printf("CAN error frame sent\n");