lib: Fix uninitialized read in msghdr_copy
authorJeremy Allison <jra@samba.org>
Wed, 8 Jun 2016 12:34:20 +0000 (14:34 +0200)
committerVolker Lendecke <vl@samba.org>
Wed, 8 Jun 2016 16:34:27 +0000 (18:34 +0200)
Signed-off-by: Jeremy Allison <jra@samba.org>
Reviewed-by: Volker Lendecke <vl@samba.org>
Autobuild-User(master): Volker Lendecke <vl@samba.org>
Autobuild-Date(master): Wed Jun  8 18:34:27 CEST 2016 on sn-devel-144

lib/util/msghdr.c

index 1aeadfc8d4ddbb98a068c0f7870cc283d0c9d8ef..0100b33e1f2aebd8fd597af2fe41dc9779f081fe 100644 (file)
@@ -204,7 +204,14 @@ ssize_t msghdr_copy(struct msghdr_buf *msg, size_t msgsize,
        bufsize = (msgsize > offsetof(struct msghdr_buf, buf)) ?
                msgsize - offsetof(struct msghdr_buf, buf) : 0;
 
-       fd_len = msghdr_prep_fds(&msg->msg, msg->buf, bufsize, fds, num_fds);
+       if (msg != NULL) {
+               msg->msg = (struct msghdr) {};
+
+               fd_len = msghdr_prep_fds(&msg->msg, msg->buf, bufsize,
+                                        fds, num_fds);
+       } else {
+               fd_len = msghdr_prep_fds(NULL, NULL, bufsize, fds, num_fds);
+       }
 
        if (fd_len == -1) {
                return -1;