blob: c3af5cbebb4d17e61da93c2738f30d5c860b45df [file]
From e752163508eaa3fddc63288e4f68fade5dbb1ad2 Mon Sep 17 00:00:00 2001
From: Chris Rauer <crauer@google.com>
Date: Thu, 21 May 2026 00:57:25 +0000
Subject: [PATCH 09/12] [dhcp-relay] Fix NULL pointer dereferences in hash
table operations
In omapip/hash.c, functions performing hash table operations (add_hash,
delete_hash_entry, and hash_lookup) did not validate whether the provided
'key' pointer was non-NULL before invoking the hash function or string
comparison functions (like strcmp):
hashno = (*table->do_hash)(key, len, ...);
...
strcmp((const char *)bp->name, key);
If a NULL key was passed (or stored in a bucket), this led to immediate
NULL pointer dereferences and program crashes.
This CL fixes the vulnerability by adding explicit NULL checks:
'if (!key)' at the entry points of add_hash, delete_hash_entry, and
hash_lookup, returning early (or returning 0 for lookup) safely without
performing any operations on NULL pointers.
BUG=510454261
TAG=agy
CONV=9ea40568-b7ac-4352-a0c8-61185ee29a27
---
omapip/hash.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/omapip/hash.c b/omapip/hash.c
index fccfb1cd..afc48cac 100644
--- a/omapip/hash.c
+++ b/omapip/hash.c
@@ -405,7 +405,7 @@ void add_hash (table, key, len, pointer, file, line)
struct hash_bucket *bp;
void *foo;
- if (!table)
+ if (!table || !key)
return;
if (!len)
@@ -440,7 +440,7 @@ void delete_hash_entry (table, key, len, file, line)
struct hash_bucket *bp, *pbp = (struct hash_bucket *)0;
void *foo;
- if (!table)
+ if (!table || !key)
return;
if (!len)
@@ -482,7 +482,7 @@ int hash_lookup (vp, table, key, len, file, line)
int hashno;
struct hash_bucket *bp;
- if (!table)
+ if (!table || !key)
return 0;
if (!len)
len = find_length(key, table->do_hash);
--
2.54.0.669.g59709faab0-goog