mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
synced 2026-09-22 09:34:56 +02:00
tracing/filters: Fix false positive match in regex_match_full()
commitc22c7b735fupstream. regex_match_full() calls strncmp(str, r->pattern, len) where len is the target field buffer size. When len is smaller than r->len (the filter pattern length), strncmp() checks only len bytes of r->pattern against str. If those len bytes match, strncmp() returns 0, resulting in a false-positive match where a shorter string in a fixed-size field matches a longer filter pattern. For example, a 4-byte static string field containing "abcd" matched the filter pattern "abcdefgh" because strncmp("abcd", "abcdefgh", 4) returned 0. In this case, @len does NOT include '\0' because it is fixed-size array. Fix this by returning 0 (no match) early when len < r->len. Fixes:1889d20922("tracing/filters: Provide basic regex support") Cc: stable@vger.kernel.org Link: https://patch.msgid.link/178528488779.124250.5571741156199253769.stgit@devnote2 Assisted-by: Antigravity:gemini-3.5-flash Signed-off-by: Masami Hiramatsu (Google) <mhiramat@kernel.org> Signed-off-by: Steven Rostedt <rostedt@goodmis.org> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
This commit is contained in:
committed by
Greg Kroah-Hartman
parent
d61ee2a27d
commit
47cef9b444
@@ -1027,6 +1027,9 @@ static int regex_match_full(char *str, struct regex *r, int len)
|
||||
if (!len)
|
||||
return strcmp(str, r->pattern) == 0;
|
||||
|
||||
if (len < r->len)
|
||||
return 0;
|
||||
|
||||
return strncmp(str, r->pattern, len) == 0;
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user