| From e752163508eaa3fddc63288e4f68fade5dbb1ad2 Mon Sep 17 00:00:00 2001 |
| From: Chris Rauer <crauer@google.com> |
| Date: Thu, 21 May 2026 00:57:25 +0000 |
| Subject: [PATCH 09/12] [dhcp-relay] Fix NULL pointer dereferences in hash |
| table operations |
| |
| In omapip/hash.c, functions performing hash table operations (add_hash, |
| delete_hash_entry, and hash_lookup) did not validate whether the provided |
| 'key' pointer was non-NULL before invoking the hash function or string |
| comparison functions (like strcmp): |
| hashno = (*table->do_hash)(key, len, ...); |
| ... |
| strcmp((const char *)bp->name, key); |
| |
| If a NULL key was passed (or stored in a bucket), this led to immediate |
| NULL pointer dereferences and program crashes. |
| |
| This CL fixes the vulnerability by adding explicit NULL checks: |
| 'if (!key)' at the entry points of add_hash, delete_hash_entry, and |
| hash_lookup, returning early (or returning 0 for lookup) safely without |
| performing any operations on NULL pointers. |
| |
| BUG=510454261 |
| TAG=agy |
| CONV=9ea40568-b7ac-4352-a0c8-61185ee29a27 |
| --- |
| omapip/hash.c | 6 +++--- |
| 1 file changed, 3 insertions(+), 3 deletions(-) |
| |
| diff --git a/omapip/hash.c b/omapip/hash.c |
| index fccfb1cd..afc48cac 100644 |
| --- a/omapip/hash.c |
| +++ b/omapip/hash.c |
| @@ -405,7 +405,7 @@ void add_hash (table, key, len, pointer, file, line) |
| struct hash_bucket *bp; |
| void *foo; |
| |
| - if (!table) |
| + if (!table || !key) |
| return; |
| |
| if (!len) |
| @@ -440,7 +440,7 @@ void delete_hash_entry (table, key, len, file, line) |
| struct hash_bucket *bp, *pbp = (struct hash_bucket *)0; |
| void *foo; |
| |
| - if (!table) |
| + if (!table || !key) |
| return; |
| |
| if (!len) |
| @@ -482,7 +482,7 @@ int hash_lookup (vp, table, key, len, file, line) |
| int hashno; |
| struct hash_bucket *bp; |
| |
| - if (!table) |
| + if (!table || !key) |
| return 0; |
| if (!len) |
| len = find_length(key, table->do_hash); |
| -- |
| 2.54.0.669.g59709faab0-goog |
| |