fix proxy_getaddrinfo crash when both node and hints are NULL

closes #620
This commit is contained in:
rofl0r
2026-08-27 13:56:22 +00:00
parent e6313ce408
commit ebf57026f4
2 changed files with 26 additions and 1 deletions

View File

@@ -996,7 +996,7 @@ err_nn:
goto err_nn;
} else if(node) {
af = ((struct sockaddr_in *) &space->sockaddr_space)->sin_family;
} else if(!node && !(hints->ai_flags & AI_PASSIVE)) {
} else if(!node && !(hints && (hints->ai_flags & AI_PASSIVE))) {
af = ((struct sockaddr_in *) &space->sockaddr_space)->sin_family = AF_INET;
memcpy(&((struct sockaddr_in *) &space->sockaddr_space)->sin_addr,
"\177\0\0\1", 4);

View File

@@ -0,0 +1,25 @@
/*
* NULL pointer dereference in proxy_getaddrinfo()
* if node == NULL && hints == NULL.
*/
#define _POSIX_C_SOURCE 200112L
#include <netdb.h>
#include <signal.h>
#include <stdio.h>
#include <unistd.h>
static void on_crash(int sig) {
fprintf(stderr, "POC_HIT: signal %d from getaddrinfo(NULL, \"80\", NULL, &res)\n", sig);
fflush(stderr);
_exit(0);
}
int main(void) {
struct addrinfo *res = 0;
int rc;
signal(SIGSEGV, on_crash);
signal(SIGBUS, on_crash);
rc = getaddrinfo(NULL, "80", NULL, &res);
fprintf(stderr, "POC_MISS: getaddrinfo returned %d\n", rc);
return 1;
}