From 1a3642cc741964f6339aeae9923bc0abbba36ce7 Mon Sep 17 00:00:00 2001 From: Matt Millett Date: Wed, 16 Sep 2026 13:53:35 -0400 Subject: [PATCH] When converting sockaddr_un to ntsa::Endpoint, treat sockaddr::sa_len as the authoritative end of the name, rather than relying on null termination --- groups/nts/ntsu/ntsu_socketutil.cpp | 27 ++++++++++++++++++++++++--- 1 file changed, 24 insertions(+), 3 deletions(-) diff --git a/groups/nts/ntsu/ntsu_socketutil.cpp b/groups/nts/ntsu/ntsu_socketutil.cpp index a3db21fc..8d3107a2 100644 --- a/groups/nts/ntsu/ntsu_socketutil.cpp +++ b/groups/nts/ntsu/ntsu_socketutil.cpp @@ -937,11 +937,28 @@ ntsa::Error SocketUtil::Impl::convert(ntsa::Endpoint* endpoint, const bsl::size_t pathOffset = offsetof(struct sockaddr_un, sun_path); - if (socketAddressSize == pathOffset) { + const bsl::size_t addressSize = + static_cast(socketAddressSize); + + if (addressSize <= pathOffset) { localName->setUnnamed(); } else { + // The address length reported by the socket API is the + // authoritative extent of 'sun_path': the field is not + // guaranteed to be null-terminated (abstract names never are, + // and a peer may supply a truncated or unterminated path). + // Bound the scan by that length, clamped to the capacity of + // the field itself, so the scan never reads bytes outside the + // address. + + bsl::size_t pathSize = addressSize - pathOffset; + if (pathSize > sizeof(socketAddressLocal->sun_path)) { + pathSize = sizeof(socketAddressLocal->sun_path); + } + const char* begin = socketAddressLocal->sun_path; + const char* limit = begin + pathSize; if (*begin == 0) { localName->setAbstract(); @@ -949,7 +966,7 @@ ntsa::Error SocketUtil::Impl::convert(ntsa::Endpoint* endpoint, } const char* end = begin; - while (*end != 0) { + while (end != limit && *end != 0) { ++end; } @@ -957,7 +974,11 @@ ntsa::Error SocketUtil::Impl::convert(ntsa::Endpoint* endpoint, localName->setUnnamed(); } else { - localName->setValue(bslstl::StringRef(begin, end)); + ntsa::Error error = + localName->setValue(bslstl::StringRef(begin, end)); + if (error) { + return error; + } } } }