Skip to content

Fix potential int overflow - #558

Open
Ti-Mis wants to merge 3 commits into
linux-audit:masterfrom
Ti-Mis:Fix-int-overflow
Open

Ti-Mis wants to merge 3 commits into
linux-audit:masterfrom
Ti-Mis:Fix-int-overflow

Conversation

@Ti-Mis

@Ti-Mis Ti-Mis commented Sep 22, 2026

Copy link
Copy Markdown

Fix: TAINTED.INT_OVERFLOW

Problem:
Potential potential integer overflow in the block_address_time_parser() function;
Potential potential integer overflow in the time_string_to_seconds() function;
Solution:
Adding constraint checking for ulong
Solution: Adding constraint checking for long
Signed-off-by: t.mishin@fobos-nt.ru
Signed-off by: dinchik@altlinux.org

Fix: TAINTED.INT_OVERFLOW

Problem:
Potential potential integer overflow in the block_address_time_parser() function;
Solution: Adding constraint checking for ulong
Signed-off-by: t.mishin@fobos-nt.ru
Signed-off by: dinchik@altlinux.org
Fix: TAINTED.INT_OVERFLOW

Problem:
Potential potential integer overflow in the time_string_to_seconds() function;
Solution: Adding constraint checking for long
Signed-off-by: t.mishin@fobos-nt.ru
Signed-off by: dinchik@altlinux.org
@stevegrubb

stevegrubb commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Thanks. This needs 2 corrections. In common/common.c, just use 0 as the minimum. No need to support negative days. Also, parenthesize the units: LONG_MAX / (HOURS) and similarly for days/months. Otherwise it turns into (LONG_MAX / 60) * 60, rather than division by 3,600.

And a follow up, ids.c uses strtoul which does accept -1 but converts it to ULONG_MAX. Probably best to just use strtol and make "i" a long then reject negative numbers there too since all supported numbers should fit in a positive long number.

@Ti-Mis

Ti-Mis commented Oct 8, 2026

Copy link
Copy Markdown
Author

I’ve made all the requested changes in a new PR. There were quite a few fixes needed for this one, so I decided to move the changes to a separate PR. #560

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants