diff options
| author | Denys Fedoryshchenko <denys.f@collabora.com> | 2026-09-07 22:08:04 +0300 |
|---|---|---|
| committer | Denys Fedoryshchenko <denys.f@collabora.com> | 2026-09-07 22:08:04 +0300 |
| commit | e014cb2cb46f9a5778fbf8a819a1ad263a911c84 (patch) | |
| tree | dae3e1642b3a7924802a99b9204a20708fc22b7b /accel-pppd/net.c | |
| parent | bd51fe8dbec25b1f130db3b4859895124841cfe8 (diff) | |
| download | accel-ppp-e014cb2cb46f9a5778fbf8a819a1ad263a911c84.tar.gz accel-ppp-e014cb2cb46f9a5778fbf8a819a1ad263a911c84.zip | |
radius: validate VRF names through Access-Accept and CoA
Reject oversized and embedded-NUL VRF attributes and allocation failures.
Keep explicit CoA lengths, restrict removal to literal 0, and bound the
session API and shared interface lookup. Preserve default VRF removal.
Adapted from Ritika Chopra's accel-ppp-ng PR #40, T8611, with the same
validation boundary extended to the CoA path.
Co-authored-by: Ritika Chopra <r.chopra@vyos.io>
Diffstat (limited to 'accel-pppd/net.c')
| -rw-r--r-- | accel-pppd/net.c | 8 |
1 files changed, 7 insertions, 1 deletions
diff --git a/accel-pppd/net.c b/accel-pppd/net.c index c619deed..b31cdf44 100644 --- a/accel-pppd/net.c +++ b/accel-pppd/net.c @@ -223,9 +223,15 @@ static int def_get_ifindex(const char *ifname) { struct kern_net *n = container_of(net, typeof(*n), net); struct ifreq ifr; + size_t len; + + if (!ifname || (len = strnlen(ifname, IFNAMSIZ)) >= IFNAMSIZ) { + log_ppp_error("invalid interface name\n"); + return -1; + } memset(&ifr, 0, sizeof(ifr)); - strcpy(ifr.ifr_name, ifname); + memcpy(ifr.ifr_name, ifname, len); if (ioctl(n->sock, SIOCGIFINDEX, &ifr)) { log_ppp_error("ioctl(SIOCGIFINDEX): %s\n", strerror(errno)); |
