Compare commits

..

1 Commits

Author SHA1 Message Date
d914e42ff6 fix(xmpp): treat disco#info result without 'from' as from the server
All checks were successful
CI Code / Check coding style (pull_request) Successful in 23s
CI Code / Check spelling (pull_request) Successful in 14s
CI Code / Linux (debian) (pull_request) Successful in 4m57s
CI Code / Linux (arch) (pull_request) Successful in 6m23s
CI Code / Linux (ubuntu) (pull_request) Successful in 7m59s
CI Code / Code Coverage (pull_request) Successful in 9m40s
CI Code / Check spelling (push) Successful in 15s
CI Code / Check coding style (push) Successful in 25s
CI Code / Code Coverage (push) Successful in 3m4s
CI Code / Linux (arch) (push) Successful in 6m25s
Publish Docker image / Push Docker image to Docker Hub (push) Successful in 7m29s
CI Code / Linux (ubuntu) (push) Successful in 8m21s
CI Code / Linux (debian) (push) Successful in 8m39s
RFC 6120 §8.1.2.1: a stanza received over a c2s stream without a 'from'
attribute must be treated as coming from the server itself. The
on-connect disco#info handler passed the absent attribute as NULL into
connection_features_received(), where g_str_hash() dereferenced the NULL
key and crashed (remotely triggerable DoS on connect).

Substitute connection_get_domain() at both disco#info handler
boundaries, and make connection_features_received() and
connection_get_features() NULL-safe as defense in depth. Add a stabber
regression test answering the on-connect disco#info with a from-less
result.

Fixes #168
2026-07-28 22:12:48 +03:00

View File

@@ -759,11 +759,11 @@ _get_from_via_jid(const char* const jid)
void void
connection_features_received(const char* const jid) connection_features_received(const char* const jid)
{ {
log_info("[CONNECTION] connection_features_received %s", jid);
const char* key = _get_from_via_jid(jid); const char* key = _get_from_via_jid(jid);
if (!key) { if (!key) {
return; return;
} }
log_info("[CONNECTION] connection_features_received %s", key);
if (g_hash_table_remove(conn.requested_features, key) && g_hash_table_size(conn.requested_features) == 0) { if (g_hash_table_remove(conn.requested_features, key) && g_hash_table_size(conn.requested_features) == 0) {
sv_ev_connection_features_received(); sv_ev_connection_features_received();
} }