curl: Add NULL checks for curl_easy_escape/unescape#2507
Open
hyder365 wants to merge 1 commit into
Open
Conversation
Member
|
How exactly can I trigger this MPD crash? |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Issue
The curl_easy_escape() and curl_easy_unescape() functions can return NULL on memory allocation failure. The original code passes the return value directly to the CurlString constructor, which stores the pointer without checking for NULL. When CurlString::c_str() is called on a NULL-holding instance, it returns NULL, which is then passed to std::string::operator+=() or the std::string(const char*) constructor, both of which exhibit undefined behavior on NULL input, typically causing a crash.
Affected functions:
If curl's memory allocation fails, MPD crashes. This can be triggered:
Solution
The patch adds NULL checks after calling curl_easy_escape() and curl_easy_unescape() before using the returned pointers:
if (!escaped) break;to skip the segment on allocation failure (uses CurlString::operator bool())if (!tmp) return {};to return an empty string on allocation failureThis preserves the existing CurlString RAII wrapper pattern while adding the necessary safety checks.