* [PATCH] gen_init_cpio: stop parsing on lines with a missing argument list
@ 2026-10-05 8:57 lzhan011
0 siblings, 0 replies; only message in thread
From: lzhan011 @ 2026-10-05 8:57 UTC (permalink / raw)
To: nathan, nsc; +Cc: linux-kbuild, linux-kernel
When a line in the cpio list consists of a file type followed only by
whitespace and no newline (e.g. "slink " as the last line of the file),
strtok(NULL, "\n") returns NULL. main() prints an error and sets ec, but
then carries on and passes the NULL args pointer to the type handler,
which hands it to sscanf() and crashes:
AddressSanitizer: SEGV on unknown address 0x000000000000
#4 __isoc99_sscanf
#5 cpio_mkslink_line usr/gen_init_cpio.c:169
Break out of the loop as is already done for the other format error, so
that the error is reported and gen_init_cpio exits with a failure status.
Found by fuzzing gen_init_cpio built with ASan/UBSan.
Reproducer:
printf 'slink ' > list && usr/gen_init_cpio list
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Assisted-by: Claude:claude-opus-5-5 ASan UBSan
Signed-off-by: lzhan011 <lzsx618@gmail.com>
---
usr/gen_init_cpio.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/usr/gen_init_cpio.c b/usr/gen_init_cpio.c
index b7296edc6..0f0c61ec2 100644
--- a/usr/gen_init_cpio.c
+++ b/usr/gen_init_cpio.c
@@ -756,6 +756,7 @@ int main (int argc, char *argv[])
"ERROR: incorrect format, newline required line %d: '%s'\n",
line_nr, line);
ec = -1;
+ break;
}
for (type_idx = 0; file_handler_table[type_idx].type; type_idx++) {
--
2.34.1
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2026-10-05 8:57 UTC | newest]
Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-05 8:57 [PATCH] gen_init_cpio: stop parsing on lines with a missing argument list lzhan011
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®