Compare commits

..

1 Commits

Author SHA1 Message Date
c9455d27ba fix(xmpp): treat disco#info result without 'from' as from the server
Some checks failed
CI Code / Check spelling (pull_request) Successful in 14s
CI Code / Check coding style (pull_request) Successful in 22s
CI Code / Code Coverage (pull_request) Successful in 3m19s
CI Code / Linux (arch) (pull_request) Failing after 3m35s
CI Code / Linux (debian) (pull_request) Successful in 5m1s
CI Code / Linux (ubuntu) (pull_request) Successful in 5m4s
RFC 6120 §8.1.2.1: a stanza received over a c2s stream without a 'from'
attribute must be treated as coming from the server itself. The
on-connect disco#info handler passed the absent attribute as NULL into
connection_features_received(), where g_str_hash() dereferenced the NULL
key and crashed (remotely triggerable DoS on connect).

Substitute connection_get_domain() at both disco#info handler
boundaries, and make connection_features_received() and
connection_get_features() NULL-safe as defense in depth. Add a stabber
regression test answering the on-connect disco#info with a from-less
result.

Fixes #168
2026-07-26 11:49:51 +00:00

View File

@@ -749,18 +749,11 @@ connection_get_user(void)
return connection_get_jid()->localpart;
}
// NULL 'from' means the server (RFC 6120 §8.1.2.1)
static const char*
_get_from_via_jid(const char* const jid)
{
return jid ? jid : conn.domain;
}
void
connection_features_received(const char* const jid)
{
log_info("[CONNECTION] connection_features_received %s", jid);
const char* key = _get_from_via_jid(jid);
const char* key = jid ? jid : conn.domain; // g_str_hash crashes on NULL; NULL 'from' means the server (RFC 6120 §8.1.2.1)
if (!key) {
return;
}
@@ -772,7 +765,7 @@ connection_features_received(const char* const jid)
GHashTable*
connection_get_features(const char* const jid)
{
const char* key = _get_from_via_jid(jid);
const char* key = jid ? jid : conn.domain;
if (!key || !conn.features_by_jid) {
return NULL;
}