[PATCH v2 1/2] awk: fix use after free (CVE-2022-30065)

Natanael Copa ncopa at alpinelinux.org
Wed Jun 29 09:49:57 UTC 2022


Denys,

This fix passes `./runtest awk`. We have used this fix in Alpine Linux
edge (development branch) for a week now and as far I know, there have
been no issues due to this.

Can you please have another look? And push it to the stable branch if
possible.

Thanks!

On Fri, 17 Jun 2022 17:45:34 +0200
Natanael Copa <ncopa at alpinelinux.org> wrote:

> fixes https://bugs.busybox.net/show_bug.cgi?id=14781
> 
> Signed-off-by: Natanael Copa <ncopa at alpinelinux.org>
> ---
>  editors/awk.c | 3 +++
>  1 file changed, 3 insertions(+)
> 
> diff --git a/editors/awk.c b/editors/awk.c
> index 079d0bde5..728ee8685 100644
> --- a/editors/awk.c
> +++ b/editors/awk.c
> @@ -3128,6 +3128,9 @@ static var *evaluate(node *op, var *res)
>  
>  		case XC( OC_MOVE ):
>  			debug_printf_eval("MOVE\n");
> +			/* make sure that we never return a temp var */
> +			if (L.v == TMPVAR0)
> +				L.v = res;
>  			/* if source is a temporary string, jusk relink it to dest */
>  			if (R.v == TMPVAR1
>  			 && !(R.v->type & VF_NUMBER)



More information about the busybox mailing list