From 5f947863b4358ba437878747072bc372cb1e855e Mon Sep 17 00:00:00 2001 From: Shell Date: Tue, 21 May 2024 19:45:08 +0800 Subject: [PATCH] [dfsv2] fixup out-of-memory access (#8973) This change addresses a potential out-of-memory access issue in the devfs filesystem component. The issue arises when the `rt_malloc` function allocates memory for a path string without accounting for the null terminator, leading to undefined behavior. As the manual documented: > DESCRIPTION > The strlen() function calculates the length of the string pointed to > by s, excluding the terminating null byte ('\0'). To fix this, the memory allocation size was increased by one byte to ensure space for the null terminator. This prevents potential out-of-memory access and ensures proper string termination. Signed-off-by: Shell --- components/dfs/dfs_v2/filesystems/devfs/devfs.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/components/dfs/dfs_v2/filesystems/devfs/devfs.c b/components/dfs/dfs_v2/filesystems/devfs/devfs.c index d2f340e105..6db468fb5f 100644 --- a/components/dfs/dfs_v2/filesystems/devfs/devfs.c +++ b/components/dfs/dfs_v2/filesystems/devfs/devfs.c @@ -427,7 +427,7 @@ mode_t dfs_devfs_device_to_mode(struct rt_device *device) static void dfs_devfs_mkdir(const char *fullpath, mode_t mode) { int len = rt_strlen(fullpath); - char *path = (char *)rt_malloc(len); + char *path = (char *)rt_malloc(len + 1); if (path) {